+
+ Lock initLock(m_lock);
+ if (m_initCount == 0) {
+ Category::getInstance(SAML_LOGCAT ".Config").crit("term without corresponding init");
+ return;
+ }
+ else if (--m_initCount > 0) {
+ return;
+ }
+
+ MessageDecoderManager.deregisterFactories();
+ MessageEncoderManager.deregisterFactories();
+ SecurityPolicyRuleManager.deregisterFactories();
+ SAMLArtifactManager.deregisterFactories();
+ EntityMatcherManager.deregisterFactories();
+ MetadataFilterManager.deregisterFactories();
+ MetadataProviderManager.deregisterFactories();
+
+ delete m_artifactMap;
+ m_artifactMap = nullptr;
+
+ if (termXMLTooling)
+ XMLToolingConfig::getConfig().term();
+
+ Category::getInstance(SAML_LOGCAT ".Config").info("%s library shutdown complete", PACKAGE_STRING);
+}
+
+void SAMLInternalConfig::generateRandomBytes(void* buf, unsigned int len)
+{
+ try {
+ if (XSECPlatformUtils::g_cryptoProvider->getRandom(reinterpret_cast<unsigned char*>(buf),len)<len)
+ throw XMLSecurityException("Unable to generate random data; was PRNG seeded?");
+ }
+ catch (XSECCryptoException& e) {
+ throw XMLSecurityException("Unable to generate random data: $1",params(1,e.getMsg()));
+ }
+}
+
+void SAMLInternalConfig::generateRandomBytes(std::string& buf, unsigned int len)
+{
+ buf.erase();
+ auto_arrayptr<unsigned char> hold(new unsigned char[len]);
+ generateRandomBytes(const_cast<unsigned char*>(hold.get()), len);
+ for (unsigned int i=0; i<len; i++)
+ buf+=(hold.get())[i];
+}
+
+XMLCh* SAMLInternalConfig::generateIdentifier()
+{
+ unsigned char key[17];
+ generateRandomBytes(key,16);
+
+ char hexform[34];
+ sprintf(hexform,"_%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x%02x",
+ key[0],key[1],key[2],key[3],key[4],key[5],key[6],key[7],
+ key[8],key[9],key[10],key[11],key[12],key[13],key[14],key[15]);
+ hexform[33]=0;
+ return XMLString::transcode(hexform);
+}
+
+string SAMLInternalConfig::hashSHA1(const char* s, bool toHex)
+{
+ return SecurityHelper::doHash("SHA1", s, strlen(s), toHex);
+}
+
+void SAMLInternalConfig::setContactPriority(const XMLCh* contactTypes)
+{
+ const XMLCh* ctype;
+ m_contactPriority.clear();
+ XMLStringTokenizer tokens(contactTypes);
+ while (tokens.hasMoreTokens()) {
+ ctype = tokens.nextToken();
+ if (ctype && *ctype)
+ m_contactPriority.push_back(ctype);
+ }
+}
+
+using namespace saml2md;
+
+const ContactPerson* SAMLInternalConfig::getContactPerson(const EntityDescriptor& entity) const
+{
+ for (vector<xstring>::const_iterator ctype = m_contactPriority.begin(); ctype != m_contactPriority.end(); ++ctype) {
+ const ContactPerson* cp = find_if(entity.getContactPersons(), *ctype == lambda::bind(&ContactPerson::getContactType, _1));
+ if (cp)
+ return cp;
+ }
+ return nullptr;
+}
+
+const ContactPerson* SAMLInternalConfig::getContactPerson(const RoleDescriptor& role) const
+{
+ for (vector<xstring>::const_iterator ctype = m_contactPriority.begin(); ctype != m_contactPriority.end(); ++ctype) {
+ const ContactPerson* cp = find_if(role.getContactPersons(), *ctype == lambda::bind(&ContactPerson::getContactType, _1));
+ if (cp)
+ return cp;
+ }
+ return getContactPerson(*(dynamic_cast<const EntityDescriptor*>(role.getParent())));
+}
+
+SignableObject::SignableObject()
+{
+}
+
+SignableObject::~SignableObject()
+{
+}
+
+RootObject::RootObject()
+{
+}
+
+RootObject::~RootObject()
+{
+}
+
+Assertion::Assertion()
+{
+}
+
+Assertion::~Assertion()
+{
+}
+
+Status::Status()
+{
+}
+
+Status::~Status()
+{
+}
+
+void opensaml::annotateException(XMLToolingException* e, const EntityDescriptor* entity, const Status* status, bool rethrow)
+{
+ time_t now = time(nullptr);
+ const RoleDescriptor* role = nullptr;
+ static bool (TimeBoundSAMLObject::* isValid)(time_t) const = &TimeBoundSAMLObject::isValid;
+
+ if (entity) {
+ const XMLObject* r = find_if(
+ entity->getOrderedChildren(),
+ (ll_dynamic_cast<const RoleDescriptor*>(_1) != ((const RoleDescriptor*)nullptr) &&
+ lambda::bind(isValid, ll_dynamic_cast<const TimeBoundSAMLObject*>(_1), now))
+ );
+ if (r)
+ role = dynamic_cast<const RoleDescriptor*>(r);
+ }
+
+ annotateException(e, role, status, rethrow);
+}
+
+void opensaml::annotateException(XMLToolingException* e, const RoleDescriptor* role, const Status* status, bool rethrow)
+{
+ if (role) {
+ auto_ptr_char id(dynamic_cast<EntityDescriptor*>(role->getParent())->getEntityID());
+ e->addProperty("entityID",id.get());
+
+ const ContactPerson* cp = SAMLConfig::getConfig().getContactPerson(*role);
+ if (cp) {
+ GivenName* fname = cp->getGivenName();
+ SurName* lname = cp->getSurName();
+ auto_ptr_char first(fname ? fname->getName() : nullptr);
+ auto_ptr_char last(lname ? lname->getName() : nullptr);
+ if (first.get() && last.get()) {
+ string contact=string(first.get()) + ' ' + last.get();
+ e->addProperty("contactName", contact.c_str());
+ }
+ else if (first.get())
+ e->addProperty("contactName", first.get());
+ else if (last.get())
+ e->addProperty("contactName", last.get());
+ const vector<EmailAddress*>& emails=cp->getEmailAddresss();
+ if (!emails.empty()) {
+ auto_ptr_char email(emails.front()->getAddress());
+ if (email.get()) {
+ if (strstr(email.get(), "mailto:") == email.get()) {
+ e->addProperty("contactEmail", email.get());
+ }
+ else {
+ string addr = string("mailto:") + email.get();
+ e->addProperty("contactEmail", addr.c_str());
+ }
+ }
+ }
+ }
+
+ auto_ptr_char eurl(role->getErrorURL());
+ if (eurl.get()) {
+ e->addProperty("errorURL",eurl.get());
+ }
+ }
+
+ if (status) {
+ auto_ptr_char sc(status->getTopStatus());
+ if (sc.get() && *sc.get())
+ e->addProperty("statusCode", sc.get());
+ if (status->getSubStatus()) {
+ auto_ptr_char sc2(status->getSubStatus());
+ if (sc2.get() && *sc.get())
+ e->addProperty("statusCode2", sc2.get());
+ }
+ if (status->getMessage()) {
+ auto_ptr_char msg(status->getMessage());
+ if (msg.get() && *msg.get())
+ e->addProperty("statusMessage", msg.get());
+ }
+ }
+
+ if (rethrow)
+ e->raise();