SAML 2.0 Core Assertion namespace unit tests.
[shibboleth/cpp-opensaml.git] / saml / saml2 / core / Assertions.h
1 /*
2  *  Copyright 2001-2006 Internet2
3  * 
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *     http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16
17 /**
18  * @file saml/saml2/core/Assertions.h
19  * 
20  * XMLObjects representing the SAML 2.0 Assertions schema
21  */
22
23 #ifndef __saml2_assertions_h__
24 #define __saml2_assertions_h__
25
26 #include <saml/signature/SignableObject.h>
27 #include <saml/util/SAMLConstants.h>
28
29 #include <xmltooling/AttributeExtensibleXMLObject.h>
30 #include <xmltooling/ElementProxy.h>
31 #include <xmltooling/SimpleElement.h>
32 #include <xmltooling/XMLObjectBuilder.h>
33 #include <xmltooling/encryption/Encryption.h>
34 #include <xmltooling/signature/KeyResolver.h>
35 #include <xmltooling/signature/Signature.h>
36 #include <xmltooling/util/DateTime.h>
37 #include <xmltooling/validation/ValidatorSuite.h>
38
39 #define DECL_SAML2OBJECTBUILDER(cname) \
40     DECL_XMLOBJECTBUILDER(SAML_API,cname,opensaml::SAMLConstants::SAML20_NS,opensaml::SAMLConstants::SAML20_PREFIX)
41
42 namespace opensaml {
43
44     /**
45      * @namespace opensaml::saml2
46      * SAML 2.0 assertion namespace
47      */
48     namespace saml2 {
49         
50         // Forward references
51         class SAML_API Assertion;
52         class SAML_API EncryptedAssertion;
53         
54         DECL_XMLOBJECT_SIMPLE(SAML_API,AssertionIDRef,AssertionID,SAML 2.0 AssertionIDRef element);
55         DECL_XMLOBJECT_SIMPLE(SAML_API,AssertionURIRef,AssertionURI,SAML 2.0 AssertionURIRef element);
56         DECL_XMLOBJECT_SIMPLE(SAML_API,Audience,AudienceURI,SAML 2.0 Audience element);
57         DECL_XMLOBJECT_SIMPLE(SAML_API,AuthnContextClassRef,Reference,SAML 2.0 AuthnContextClassRef element);
58         DECL_XMLOBJECT_SIMPLE(SAML_API,AuthnContextDeclRef,Reference,SAML 2.0 AuthnContextDeclRef element);
59         DECL_XMLOBJECT_SIMPLE(SAML_API,AuthenticatingAuthority,ID,SAML 2.0 AuthenticatingAuthority element);
60
61         BEGIN_XMLOBJECT(SAML_API,EncryptedElementType,xmltooling::XMLObject,SAML 2.0 EncryptedElementType type);
62             DECL_TYPED_FOREIGN_CHILD(EncryptedData,xmlencryption);
63             DECL_TYPED_FOREIGN_CHILDREN(EncryptedKey,xmlencryption);
64             /** EncryptedElementType local name */
65             static const XMLCh TYPE_NAME[];
66             
67             /**
68              * Decrypts the element using a standard approach based on a wrapped decryption key
69              * inside the message. The key decryption key should be supplied using the provided
70              * resolver. The recipient name may be used when multiple encrypted keys are found.
71              * The object returned will be unmarshalled around the decrypted DOM element, but the
72              * DOM itself will be released. 
73              * 
74              * @param KEKresolver   resolver supplying key decryption key
75              * @param recipient     identifier naming the recipient (the entity performing the decryption)
76              * @return  the decrypted and unmarshalled object
77              */
78             virtual xmltooling::XMLObject* decrypt(xmlsignature::KeyResolver* KEKresolver, const XMLCh* recipient) const=0;
79         END_XMLOBJECT;
80
81         BEGIN_XMLOBJECT(SAML_API,EncryptedID,EncryptedElementType,SAML 2.0 EncryptedID element);
82         END_XMLOBJECT;
83
84         BEGIN_XMLOBJECT(SAML_API,BaseID,xmltooling::XMLObject,SAML 2.0 BaseIDAbstractType abstract type);
85             DECL_STRING_ATTRIB(NameQualifier,NAMEQUALIFIER);
86             DECL_STRING_ATTRIB(SPNameQualifier,SPNAMEQUALIFIER);
87         END_XMLOBJECT;
88
89         BEGIN_XMLOBJECT(SAML_API,NameIDType,xmltooling::SimpleElement,SAML 2.0 NameIDType type);
90             DECL_STRING_ATTRIB(NameQualifier,NAMEQUALIFIER);
91             DECL_STRING_ATTRIB(SPNameQualifier,SPNAMEQUALIFIER);
92             DECL_STRING_ATTRIB(Format,FORMAT);
93             DECL_STRING_ATTRIB(SPProvidedID,SPPROVIDEDID);
94             DECL_XMLOBJECT_CONTENT(Name);
95             /** NameIDType local name */
96             static const XMLCh TYPE_NAME[];
97         END_XMLOBJECT;
98
99         BEGIN_XMLOBJECT(SAML_API,NameID,NameIDType,SAML 2.0 NameID element);
100         END_XMLOBJECT;
101
102         BEGIN_XMLOBJECT(SAML_API,Issuer,NameIDType,SAML 2.0 Issuer element);
103         END_XMLOBJECT;
104
105         BEGIN_XMLOBJECT(SAML_API,Condition,xmltooling::XMLObject,SAML 2.0 Condition element);
106         END_XMLOBJECT;
107         
108         BEGIN_XMLOBJECT(SAML_API,AudienceRestriction,Condition,SAML 2.0 AudienceRestriction element);
109             DECL_TYPED_CHILDREN(Audience);
110             /** AudienceRestrictionType local name */
111             static const XMLCh TYPE_NAME[];
112         END_XMLOBJECT;
113
114         BEGIN_XMLOBJECT(SAML_API,OneTimeUse,Condition,SAML 2.0 OneTimeUse element);
115             /** OneTimeUseType local name */
116             static const XMLCh TYPE_NAME[];
117         END_XMLOBJECT;
118
119         BEGIN_XMLOBJECT(SAML_API,ProxyRestriction,Condition,SAML 2.0 ProxyRestriction element);
120             DECL_INTEGER_ATTRIB(Count,COUNT);
121             DECL_TYPED_CHILDREN(Audience);
122             /** ProxyRestrictionType local name */
123             static const XMLCh TYPE_NAME[];
124         END_XMLOBJECT;
125
126         BEGIN_XMLOBJECT(SAML_API,Conditions,xmltooling::XMLObject,SAML 2.0 Conditions element);
127             DECL_DATETIME_ATTRIB(NotBefore,NOTBEFORE);
128             DECL_DATETIME_ATTRIB(NotOnOrAfter,NOTONORAFTER);
129             DECL_TYPED_CHILDREN(AudienceRestriction);
130             DECL_TYPED_CHILDREN(OneTimeUse);
131             DECL_TYPED_CHILDREN(ProxyRestriction);
132             DECL_TYPED_CHILDREN(Condition);
133             /** ConditionsType local name */
134             static const XMLCh TYPE_NAME[];
135         END_XMLOBJECT;
136
137         BEGIN_XMLOBJECT2(SAML_API,SubjectConfirmationData,xmltooling::ElementProxy,xmltooling::AttributeExtensibleXMLObject,SAML 2.0 SubjectConfirmationData element);
138             DECL_DATETIME_ATTRIB(NotBefore,NOTBEFORE);
139             DECL_DATETIME_ATTRIB(NotOnOrAfter,NOTONORAFTER);
140             DECL_STRING_ATTRIB(Recipient,RECIPIENT);
141             DECL_STRING_ATTRIB(InResponseTo,INRESPONSETO);
142             DECL_STRING_ATTRIB(Address,ADDRESS);
143             DECL_XMLOBJECT_CONTENT(Data);
144         END_XMLOBJECT;
145
146         BEGIN_XMLOBJECT(SAML_API,KeyInfoConfirmationDataType,xmltooling::AttributeExtensibleXMLObject,SAML 2.0 KeyInfoConfirmationDataType type);
147             DECL_DATETIME_ATTRIB(NotBefore,NOTBEFORE);
148             DECL_DATETIME_ATTRIB(NotOnOrAfter,NOTONORAFTER);
149             DECL_STRING_ATTRIB(Recipient,RECIPIENT);
150             DECL_STRING_ATTRIB(InResponseTo,INRESPONSETO);
151             DECL_STRING_ATTRIB(Address,ADDRESS);
152             DECL_TYPED_FOREIGN_CHILDREN(KeyInfo,xmlsignature);
153             /** KeyInfoConfirmationDataType local name */
154             static const XMLCh TYPE_NAME[];
155         END_XMLOBJECT;
156         
157         BEGIN_XMLOBJECT(SAML_API,SubjectConfirmation,xmltooling::XMLObject,SAML 2.0 SubjectConfirmation element);
158             DECL_STRING_ATTRIB(Method,METHOD);
159             DECL_TYPED_CHILD(BaseID);
160             DECL_TYPED_CHILD(NameID);
161             DECL_TYPED_CHILD(EncryptedID);
162             DECL_XMLOBJECT_CHILD(SubjectConfirmationData);
163             DECL_TYPED_CHILD(KeyInfoConfirmationDataType);
164             /** SubjectConfirmationType local name */
165             static const XMLCh TYPE_NAME[];
166         END_XMLOBJECT;
167
168         BEGIN_XMLOBJECT(SAML_API,Subject,xmltooling::XMLObject,SAML 2.0 Subject element);
169             DECL_TYPED_CHILD(BaseID);
170             DECL_TYPED_CHILD(NameID);
171             DECL_TYPED_CHILD(EncryptedID);
172             DECL_TYPED_CHILDREN(SubjectConfirmation);
173             /** SubjectType local name */
174             static const XMLCh TYPE_NAME[];
175         END_XMLOBJECT;
176
177         BEGIN_XMLOBJECT(SAML_API,Statement,xmltooling::XMLObject,SAML 2.0 Statement element);
178         END_XMLOBJECT;
179
180         BEGIN_XMLOBJECT(SAML_API,SubjectLocality,xmltooling::XMLObject,SAML 2.0 SubjectLocality element);
181             DECL_STRING_ATTRIB(Address,ADDRESS);
182             DECL_STRING_ATTRIB(DNSName,DNSNAME);
183             /** SubjectLocalityType local name */
184             static const XMLCh TYPE_NAME[];
185         END_XMLOBJECT;
186
187         BEGIN_XMLOBJECT2(SAML_API,AuthnContextDecl,xmltooling::ElementProxy,xmltooling::AttributeExtensibleXMLObject,SAML 2.0 AuthnContextDecl element);
188         END_XMLOBJECT;
189
190         BEGIN_XMLOBJECT(SAML_API,AuthnContext,xmltooling::XMLObject,SAML 2.0 AuthnContext element);
191             DECL_TYPED_CHILD(AuthnContextClassRef);
192             DECL_XMLOBJECT_CHILD(AuthnContextDecl);
193             DECL_TYPED_CHILD(AuthnContextDeclRef);
194             DECL_TYPED_CHILDREN(AuthenticatingAuthority);
195             /** AuthnContextType local name */
196             static const XMLCh TYPE_NAME[];
197         END_XMLOBJECT;
198
199         BEGIN_XMLOBJECT(SAML_API,AuthnStatement,Statement,SAML 2.0 AuthnStatement element);
200             DECL_DATETIME_ATTRIB(AuthnInstant,AUTHNINSTANT);
201             DECL_STRING_ATTRIB(SessionIndex,SESSIONINDEX);
202             DECL_DATETIME_ATTRIB(SessionNotOnOrAfter,SESSIONNOTONORAFTER);
203             DECL_TYPED_CHILD(SubjectLocality);
204             DECL_TYPED_CHILD(AuthnContext);
205             /** AuthnStatementType local name */
206             static const XMLCh TYPE_NAME[];
207         END_XMLOBJECT;
208
209         BEGIN_XMLOBJECT(SAML_API,Action,xmltooling::SimpleElement,SAML 2.0 Action element);
210             DECL_STRING_ATTRIB(Namespace,NAMESPACE);
211             DECL_XMLOBJECT_CONTENT(Action);
212             /** ActionType local name */
213             static const XMLCh TYPE_NAME[];
214         END_XMLOBJECT;
215
216         BEGIN_XMLOBJECT(SAML_API,Evidence,xmltooling::XMLObject,SAML 2.0 Evidence element);
217             DECL_TYPED_CHILDREN(AssertionIDRef);
218             DECL_TYPED_CHILDREN(AssertionURIRef);
219             DECL_TYPED_CHILDREN(Assertion);
220             DECL_TYPED_CHILDREN(EncryptedAssertion);
221             /** EvidenceType local name */
222             static const XMLCh TYPE_NAME[];
223         END_XMLOBJECT;
224
225         BEGIN_XMLOBJECT(SAML_API,AuthzDecisionStatement,Statement,SAML 2.0 AuthzDecisionStatement element);
226             DECL_STRING_ATTRIB(Resource,RESOURCE);
227             DECL_STRING_ATTRIB(Decision,DECISION);
228             DECL_TYPED_CHILDREN(Action);
229             DECL_TYPED_CHILD(Evidence);
230             /** AuthzDecisionStatementType local name */
231             static const XMLCh TYPE_NAME[];
232             /** Permit Decision */
233             static const XMLCh DECISION_PERMIT[];
234             /** Deny Decision */
235             static const XMLCh DECISION_DENY[];
236             /** Indeterminate Decision */
237             static const XMLCh DECISION_INDETERMINATE[];
238         END_XMLOBJECT;
239
240         BEGIN_XMLOBJECT2(SAML_API,AttributeValue,xmltooling::ElementProxy,xmltooling::AttributeExtensibleXMLObject,SAML 2.0 AttributeValue element);
241         END_XMLOBJECT;
242
243         BEGIN_XMLOBJECT(SAML_API,Attribute,xmltooling::AttributeExtensibleXMLObject,SAML 2.0 Attribute element);
244             DECL_STRING_ATTRIB(Name,NAME);
245             DECL_STRING_ATTRIB(NameFormat,NAMEFORMAT);
246             DECL_STRING_ATTRIB(FriendlyName,FRIENDLYNAME);
247             DECL_XMLOBJECT_CHILDREN(AttributeValue);
248             /** AttributeType local name */
249             static const XMLCh TYPE_NAME[];
250         END_XMLOBJECT;
251
252         BEGIN_XMLOBJECT(SAML_API,EncryptedAttribute,EncryptedElementType,SAML 2.0 EncryptedAttribute element);
253         END_XMLOBJECT;
254
255         BEGIN_XMLOBJECT(SAML_API,AttributeStatement,Statement,SAML 2.0 AttributeStatement element);
256             DECL_TYPED_CHILDREN(Attribute);
257             DECL_TYPED_CHILDREN(EncryptedAttribute);
258             /** AttributeStatementType local name */
259             static const XMLCh TYPE_NAME[];
260         END_XMLOBJECT;
261
262         BEGIN_XMLOBJECT(SAML_API,EncryptedAssertion,EncryptedElementType,SAML 2.0 EncryptedAssertion element);
263         END_XMLOBJECT;
264
265         BEGIN_XMLOBJECT(SAML_API,Advice,xmltooling::XMLObject,SAML 2.0 Advice element);
266             DECL_TYPED_CHILDREN(AssertionIDRef);
267             DECL_TYPED_CHILDREN(AssertionURIRef);
268             DECL_TYPED_CHILDREN(Assertion);
269             DECL_TYPED_CHILDREN(EncryptedAssertion);
270             DECL_XMLOBJECT_CHILDREN(Other);
271             /** AdviceType local name */
272             static const XMLCh TYPE_NAME[];
273         END_XMLOBJECT;
274
275         BEGIN_XMLOBJECT(SAML_API,Assertion,SignableObject,SAML 2.0 Assertion element);
276             DECL_STRING_ATTRIB(Version,VER);
277             DECL_STRING_ATTRIB(ID,ID);
278             DECL_DATETIME_ATTRIB(IssueInstant,ISSUEINSTANT);
279             DECL_TYPED_CHILD(Issuer);
280             DECL_TYPED_FOREIGN_CHILD(Signature,xmlsignature);
281             DECL_TYPED_CHILD(Subject);
282             DECL_TYPED_CHILD(Conditions);
283             DECL_TYPED_CHILD(Advice);
284             DECL_TYPED_CHILDREN(Statement);
285             DECL_TYPED_CHILDREN(AuthnStatement);
286             DECL_TYPED_CHILDREN(AttributeStatement);
287             DECL_TYPED_CHILDREN(AuthzDecisionStatement);
288             /** AssertionType local name */
289             static const XMLCh TYPE_NAME[];
290         END_XMLOBJECT;
291
292         DECL_SAML2OBJECTBUILDER(Action);
293         DECL_SAML2OBJECTBUILDER(Advice);
294         DECL_SAML2OBJECTBUILDER(Assertion);
295         DECL_SAML2OBJECTBUILDER(AssertionIDRef);
296         DECL_SAML2OBJECTBUILDER(AssertionURIRef);
297         DECL_SAML2OBJECTBUILDER(Attribute);
298         DECL_SAML2OBJECTBUILDER(AttributeStatement);
299         DECL_SAML2OBJECTBUILDER(AttributeValue);
300         DECL_SAML2OBJECTBUILDER(Audience);
301         DECL_SAML2OBJECTBUILDER(AudienceRestriction);
302         DECL_SAML2OBJECTBUILDER(AuthenticatingAuthority);
303         DECL_SAML2OBJECTBUILDER(AuthnContext);
304         DECL_SAML2OBJECTBUILDER(AuthnContextClassRef);
305         DECL_SAML2OBJECTBUILDER(AuthnContextDecl);
306         DECL_SAML2OBJECTBUILDER(AuthnContextDeclRef);
307         DECL_SAML2OBJECTBUILDER(AuthnStatement);
308         DECL_SAML2OBJECTBUILDER(AuthzDecisionStatement);
309         DECL_SAML2OBJECTBUILDER(Conditions);
310         DECL_SAML2OBJECTBUILDER(EncryptedAssertion);
311         DECL_SAML2OBJECTBUILDER(EncryptedAttribute);
312         DECL_SAML2OBJECTBUILDER(EncryptedID);
313         DECL_SAML2OBJECTBUILDER(Evidence);
314         DECL_SAML2OBJECTBUILDER(Issuer);
315         DECL_SAML2OBJECTBUILDER(NameID);
316         DECL_SAML2OBJECTBUILDER(OneTimeUse);
317         DECL_SAML2OBJECTBUILDER(ProxyRestriction);
318         DECL_SAML2OBJECTBUILDER(Subject);
319         DECL_SAML2OBJECTBUILDER(SubjectConfirmation);
320         DECL_SAML2OBJECTBUILDER(SubjectConfirmationData);
321         DECL_SAML2OBJECTBUILDER(SubjectLocality);
322         
323         /**
324          * Builder for NameIDType objects.
325          * 
326          * This is customized to force the element name to be specified.
327          */
328         class SAML_API NameIDTypeBuilder : public xmltooling::XMLObjectBuilder {
329         public:
330             virtual ~NameIDTypeBuilder() {}
331             /** Builder that allows element/type override. */
332             virtual NameIDType* buildObject(
333                 const XMLCh* nsURI, const XMLCh* localName, const XMLCh* prefix=NULL, const xmltooling::QName* schemaType=NULL
334                 ) const;
335         
336             /** Singleton builder. */
337             static NameIDType* buildNameIDType(const XMLCh* nsURI, const XMLCh* localName, const XMLCh* prefix=NULL) {
338                 const NameIDTypeBuilder* b = dynamic_cast<const NameIDTypeBuilder*>(
339                     XMLObjectBuilder::getBuilder(xmltooling::QName(SAMLConstants::SAML20_NS,NameIDType::TYPE_NAME))
340                     );
341                 if (b) {
342                     xmltooling::QName schemaType(SAMLConstants::SAML20_NS,NameIDType::TYPE_NAME,SAMLConstants::SAML20_PREFIX);
343                     return b->buildObject(nsURI, localName, prefix, &schemaType);
344                 }
345                 throw xmltooling::XMLObjectException("Unable to obtain typed builder for NameIDType.");
346             }
347         };
348
349         /**
350          * Builder for KeyInfoConfirmationDataType objects.
351          * 
352          * This is customized to return a SubjectConfirmationData element with an
353          * xsi:type of KeyInfoConfirmationDataType.
354          */
355         class SAML_API KeyInfoConfirmationDataTypeBuilder : public xmltooling::XMLObjectBuilder {
356         public:
357             virtual ~KeyInfoConfirmationDataTypeBuilder() {}
358             /** Default builder. */
359             virtual KeyInfoConfirmationDataType* buildObject() const {
360                 xmltooling::QName schemaType(
361                     SAMLConstants::SAML20_NS,KeyInfoConfirmationDataType::TYPE_NAME,SAMLConstants::SAML20_PREFIX
362                     );
363                 return buildObject(
364                     SAMLConstants::SAML20_NS,KeyInfoConfirmationDataType::LOCAL_NAME,SAMLConstants::SAML20_PREFIX,&schemaType
365                     );
366             }
367             /** Builder that allows element/type override. */
368             virtual KeyInfoConfirmationDataType* buildObject(
369                 const XMLCh* nsURI, const XMLCh* localName, const XMLCh* prefix=NULL, const xmltooling::QName* schemaType=NULL
370                 ) const;
371         
372             /** Singleton builder. */
373             static KeyInfoConfirmationDataType* buildKeyInfoConfirmationDataType() {
374                 const KeyInfoConfirmationDataTypeBuilder* b = dynamic_cast<const KeyInfoConfirmationDataTypeBuilder*>(
375                     XMLObjectBuilder::getBuilder(xmltooling::QName(SAMLConstants::SAML20_NS,KeyInfoConfirmationDataType::TYPE_NAME))
376                     );
377                 if (b)
378                     return b->buildObject();
379                 throw xmltooling::XMLObjectException("Unable to obtain typed builder for KeyInfoConfirmationDataType.");
380             }
381         };
382         
383         /**
384          * Registers builders and validators for SAML 2.0 Assertion classes into the runtime.
385          */
386         void SAML_API registerAssertionClasses();
387
388         /**
389          * Validator suite for SAML 2.0 Assertion schema validation.
390          */
391         extern SAML_API xmltooling::ValidatorSuite AssertionSchemaValidators;
392     };
393 };
394
395 #endif /* __saml2_assertions_h__ */