2 * Licensed to the University Corporation for Advanced Internet
3 * Development, Inc. (UCAID) under one or more contributor license
4 * agreements. See the NOTICE file distributed with this work for
5 * additional information regarding copyright ownership.
7 * UCAID licenses this file to you under the Apache License,
8 * Version 2.0 (the "License"); you may not use this file except
9 * in compliance with the License. You may obtain a copy of the
12 * http://www.apache.org/licenses/LICENSE-2.0
14 * Unless required by applicable law or agreed to in writing,
15 * software distributed under the License is distributed on an
16 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND,
17 * either express or implied. See the License for the specific
18 * language governing permissions and limitations under the License.
22 * WhitelistMetadataFilter.cpp
24 * Removes non-whitelisted entities from a metadata instance
28 #include "saml2/metadata/Metadata.h"
29 #include "saml2/metadata/MetadataFilter.h"
31 #include <boost/bind.hpp>
32 #include <boost/iterator/indirect_iterator.hpp>
33 #include <xmltooling/logging.h>
34 #include <xmltooling/util/NDC.h>
36 using namespace opensaml::saml2md;
37 using namespace xmltooling::logging;
38 using namespace xmltooling;
39 using namespace boost;
45 class SAML_DLLLOCAL WhitelistMetadataFilter : public MetadataFilter
48 WhitelistMetadataFilter(const DOMElement* e);
49 ~WhitelistMetadataFilter() {}
51 const char* getId() const { return WHITELIST_METADATA_FILTER; }
52 void doFilter(XMLObject& xmlObject) const;
55 void doFilter(EntitiesDescriptor& entities) const;
57 bool found(const XMLCh* id) const {
60 return m_set.count(id)==1;
66 MetadataFilter* SAML_DLLLOCAL WhitelistMetadataFilterFactory(const DOMElement* const & e)
68 return new WhitelistMetadataFilter(e);
74 static const XMLCh Include[] = UNICODE_LITERAL_7(I,n,c,l,u,d,e);
76 WhitelistMetadataFilter::WhitelistMetadataFilter(const DOMElement* e)
78 e = XMLHelper::getFirstChildElement(e);
80 if (XMLString::equals(e->getLocalName(), Include) && e->hasChildNodes()) {
81 m_set.insert(e->getFirstChild()->getTextContent());
83 e = XMLHelper::getNextSiblingElement(e);
87 void WhitelistMetadataFilter::doFilter(XMLObject& xmlObject) const
94 doFilter(dynamic_cast<EntitiesDescriptor&>(xmlObject));
101 EntityDescriptor& entity = dynamic_cast<EntityDescriptor&>(xmlObject);
102 if (!found(entity.getEntityID()))
103 throw MetadataFilterException(WHITELIST_METADATA_FILTER" MetadataFilter instructed to filter the root/only entity in the metadata.");
109 throw MetadataFilterException(WHITELIST_METADATA_FILTER" MetadataFilter was given an improper metadata instance to filter.");
112 void WhitelistMetadataFilter::doFilter(EntitiesDescriptor& entities) const
114 Category& log=Category::getInstance(SAML_LOGCAT".MetadataFilter."WHITELIST_METADATA_FILTER);
116 VectorOf(EntityDescriptor) v=entities.getEntityDescriptors();
117 for (VectorOf(EntityDescriptor)::size_type i=0; i<v.size(); ) {
118 const XMLCh* id=v[i]->getEntityID();
120 auto_ptr_char id2(id);
121 log.info("filtering out non-whitelisted entity (%s)", id2.get());
122 v.erase(v.begin() + i);
129 const vector<EntitiesDescriptor*>& groups=const_cast<const EntitiesDescriptor&>(entities).getEntitiesDescriptors();
131 make_indirect_iterator(groups.begin()), make_indirect_iterator(groups.end()),
133 static_cast<void (WhitelistMetadataFilter::*)(EntitiesDescriptor&) const>(&WhitelistMetadataFilter::doFilter), this, _1