c54ea905a4110a50c4afb280d51304fa69dcbe49
[shibboleth/cpp-opensaml.git] / saml / saml1 / core / impl / ProtocolsSchemaValidators.cpp
1 /*
2 *  Copyright 2001-2007 Internet2
3  *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *     http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16
17 /**
18  * ProtocolsSchemaValidators.cpp
19  *
20  * Schema-based validators for SAML 1.x Protocols classes
21  */
22
23 #include "internal.h"
24 #include "exceptions.h"
25 #include "saml1/core/Protocols.h"
26
27 #include <xmltooling/validation/ValidatorSuite.h>
28
29 using namespace opensaml::saml1p;
30 using namespace opensaml::saml1;
31 using namespace opensaml;
32 using namespace xmltooling;
33 using namespace std;
34 using samlconstants::SAML1P_NS;
35
36 namespace opensaml {
37     namespace saml1p {
38
39         XMLOBJECTVALIDATOR_SIMPLE(SAML_DLLLOCAL,AssertionArtifact);
40         XMLOBJECTVALIDATOR_SIMPLE(SAML_DLLLOCAL,StatusMessage);
41
42         BEGIN_XMLOBJECTVALIDATOR(SAML_DLLLOCAL,RespondWith);
43             XMLOBJECTVALIDATOR_REQUIRE(RespondWith,QName);
44         END_XMLOBJECTVALIDATOR;
45
46         BEGIN_XMLOBJECTVALIDATOR(SAML_DLLLOCAL,AuthenticationQuery);
47             XMLOBJECTVALIDATOR_REQUIRE(AuthenticationQuery,AuthenticationMethod);
48             XMLOBJECTVALIDATOR_REQUIRE(AuthenticationQuery,Subject);
49         END_XMLOBJECTVALIDATOR;
50
51         BEGIN_XMLOBJECTVALIDATOR(SAML_DLLLOCAL,AttributeQuery);
52             XMLOBJECTVALIDATOR_REQUIRE(AttributeQuery,Subject);
53         END_XMLOBJECTVALIDATOR;
54
55         BEGIN_XMLOBJECTVALIDATOR(SAML_DLLLOCAL,AuthorizationDecisionQuery);
56             XMLOBJECTVALIDATOR_REQUIRE(AuthorizationDecisionQuery,Subject);
57             XMLOBJECTVALIDATOR_REQUIRE(AuthorizationDecisionQuery,Resource);
58             XMLOBJECTVALIDATOR_NONEMPTY(AuthorizationDecisionQuery,Action);
59         END_XMLOBJECTVALIDATOR;
60
61         BEGIN_XMLOBJECTVALIDATOR(SAML_DLLLOCAL,Request);
62             XMLOBJECTVALIDATOR_REQUIRE(Request,RequestID);
63             XMLOBJECTVALIDATOR_REQUIRE(Request,IssueInstant);
64             pair<bool,int> minor=ptr->getMinorVersion();
65             if (!minor.first)
66                 throw ValidationException("Request must have MinorVersion");
67             int count=0;
68             if (ptr->getQuery()!=NULL)
69                 count++;
70             if (!ptr->getAssertionIDReferences().empty())
71                 count++;
72             if (!ptr->getAssertionArtifacts().empty())
73                 count++;
74             if (count != 1)
75                 throw ValidationException("Request must have either a query, >0 assertion references, or >0 artifacts.");
76         END_XMLOBJECTVALIDATOR;
77
78         BEGIN_XMLOBJECTVALIDATOR(SAML_DLLLOCAL,StatusCode);
79             XMLOBJECTVALIDATOR_REQUIRE(StatusCode,Value);
80         END_XMLOBJECTVALIDATOR;
81
82         BEGIN_XMLOBJECTVALIDATOR(SAML_DLLLOCAL,Status);
83             XMLOBJECTVALIDATOR_REQUIRE(Status,StatusCode);
84             const xmltooling::QName* value=ptr->getStatusCode()->getValue();
85             if (!value || (*value!=StatusCode::SUCCESS && *value!=StatusCode::REQUESTER &&
86                 *value!=StatusCode::RESPONDER && *value!=StatusCode::VERSIONMISMATCH))
87                 throw ValidationException("Top-level status code not one of the allowable values.");
88         END_XMLOBJECTVALIDATOR;
89
90         BEGIN_XMLOBJECTVALIDATOR(SAML_DLLLOCAL,Response);
91             XMLOBJECTVALIDATOR_REQUIRE(Response,ResponseID);
92             XMLOBJECTVALIDATOR_REQUIRE(Response,IssueInstant);
93             XMLOBJECTVALIDATOR_REQUIRE(Response,Status);
94             pair<bool,int> minor=ptr->getMinorVersion();
95             if (!minor.first)
96                 throw ValidationException("Response must have MinorVersion");
97         END_XMLOBJECTVALIDATOR;
98     };
99 };
100
101 #define REGISTER_ELEMENT(cname) \
102     q=xmltooling::QName(SAML1P_NS,cname::LOCAL_NAME); \
103     XMLObjectBuilder::registerBuilder(q,new cname##Builder()); \
104     SchemaValidators.registerValidator(q,new cname##SchemaValidator())
105
106 #define REGISTER_TYPE(cname) \
107     q=xmltooling::QName(SAML1P_NS,cname::TYPE_NAME); \
108     XMLObjectBuilder::registerBuilder(q,new cname##Builder()); \
109     SchemaValidators.registerValidator(q,new cname##SchemaValidator())
110
111 #define REGISTER_ELEMENT_NOVAL(cname) \
112     q=xmltooling::QName(SAML1P_NS,cname::LOCAL_NAME); \
113     XMLObjectBuilder::registerBuilder(q,new cname##Builder());
114
115 #define REGISTER_TYPE_NOVAL(cname) \
116     q=xmltooling::QName(SAML1P_NS,cname::TYPE_NAME); \
117     XMLObjectBuilder::registerBuilder(q,new cname##Builder());
118
119 void opensaml::saml1p::registerProtocolClasses() {
120     xmltooling::QName q;
121     REGISTER_ELEMENT(AssertionArtifact);
122     REGISTER_ELEMENT(AttributeQuery);
123     REGISTER_ELEMENT(AuthenticationQuery);
124     REGISTER_ELEMENT(AuthorizationDecisionQuery);
125     REGISTER_ELEMENT_NOVAL(Query);
126     REGISTER_ELEMENT(Request);
127     REGISTER_ELEMENT(RespondWith);
128     REGISTER_ELEMENT(Response);
129     REGISTER_ELEMENT(Status);
130     REGISTER_ELEMENT(StatusCode);
131     REGISTER_ELEMENT_NOVAL(StatusDetail);
132     REGISTER_ELEMENT(StatusMessage);
133     REGISTER_TYPE(AttributeQuery);
134     REGISTER_TYPE(AuthenticationQuery);
135     REGISTER_TYPE(AuthorizationDecisionQuery);
136     REGISTER_TYPE(Request);
137     REGISTER_TYPE(Response);
138     REGISTER_TYPE(Status);
139     REGISTER_TYPE(StatusCode);
140     REGISTER_TYPE_NOVAL(StatusDetail);
141 }