/*
- * Copyright 2001-2009 Internet2
+ * Copyright 2001-2010 Internet2
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
#include "binding/SecurityPolicyRule.h"
#include "saml2/core/Assertions.h"
+#include <xercesc/util/XMLUniDefs.hpp>
+
using namespace opensaml::saml2md;
using namespace opensaml::saml2;
using namespace opensaml;
conf.SecurityPolicyRuleManager.registerFactory(DELEGATION_POLICY_RULE, saml2::DelegationRestrictionRuleFactory);
}
-SecurityPolicy::IssuerMatchingPolicy SecurityPolicy::m_defaultMatching;
+SecurityPolicyRule::SecurityPolicyRule()
+{
+}
+
+SecurityPolicyRule::~SecurityPolicyRule()
+{
+}
SecurityPolicy::SecurityPolicy(
const saml2md::MetadataProvider* metadataProvider,
const xmltooling::QName* role,
const xmltooling::TrustEngine* trustEngine,
bool validate
- ) : m_metadataCriteria(NULL),
+ ) : m_metadataCriteria(nullptr),
m_issueInstant(0),
- m_issuer(NULL),
- m_issuerRole(NULL),
+ m_issuer(nullptr),
+ m_issuerRole(nullptr),
m_authenticated(false),
- m_matchingPolicy(NULL),
+ m_matchingPolicy(nullptr),
m_metadata(metadataProvider),
- m_role(NULL),
+ m_role(nullptr),
m_trust(trustEngine),
m_validate(validate),
m_entityOnly(true),
delete m_issuer;
}
-void SecurityPolicy::reset(bool messageOnly)
+const MetadataProvider* SecurityPolicy::getMetadataProvider() const
{
- _reset(messageOnly);
-}
-
-void SecurityPolicy::_reset(bool messageOnly)
-{
- m_messageID.erase();
- m_issueInstant=0;
- if (!messageOnly) {
- delete m_issuer;
- m_issuer=NULL;
- m_issuerRole=NULL;
- m_authenticated=false;
- }
+ return m_metadata;
}
MetadataProvider::Criteria& SecurityPolicy::getMetadataProviderCriteria() const
return *m_metadataCriteria;
}
-void SecurityPolicy::setMetadataProviderCriteria(saml2md::MetadataProvider::Criteria* criteria)
+const xmltooling::QName* SecurityPolicy::getRole() const
+{
+ return m_role;
+}
+
+const TrustEngine* SecurityPolicy::getTrustEngine() const
+{
+ return m_trust;
+}
+
+bool SecurityPolicy::getValidating() const
+{
+ return m_validate;
+}
+
+bool SecurityPolicy::requireEntityIssuer() const
+{
+ return m_entityOnly;
+}
+
+const vector<xstring>& SecurityPolicy::getAudiences() const
+{
+ return m_audiences;
+}
+
+vector<xstring>& SecurityPolicy::getAudiences()
+{
+ return m_audiences;
+}
+
+time_t SecurityPolicy::getTime() const
+{
+ if (m_ts == 0)
+ return m_ts = time(nullptr);
+ return m_ts;
+}
+
+const XMLCh* SecurityPolicy::getCorrelationID() const
+{
+ return m_correlationID.c_str();
+}
+
+vector<const SecurityPolicyRule*>& SecurityPolicy::getRules()
+{
+ return m_rules;
+}
+
+void SecurityPolicy::setMetadataProvider(const MetadataProvider* metadata)
+{
+ m_metadata = metadata;
+}
+
+void SecurityPolicy::setMetadataProviderCriteria(MetadataProvider::Criteria* criteria)
{
if (m_metadataCriteria)
delete m_metadataCriteria;
m_metadataCriteria=criteria;
}
+void SecurityPolicy::setRole(const xmltooling::QName* role)
+{
+ delete m_role;
+ m_role = role ? new xmltooling::QName(*role) : nullptr;
+}
+
+void SecurityPolicy::setTrustEngine(const TrustEngine* trust)
+{
+ m_trust = trust;
+}
+
+void SecurityPolicy::setValidating(bool validate)
+{
+ m_validate = validate;
+}
+
+void SecurityPolicy::requireEntityIssuer(bool entityOnly)
+{
+ m_entityOnly = entityOnly;
+}
+
+void SecurityPolicy::setTime(time_t ts)
+{
+ m_ts = ts;
+}
+
+void SecurityPolicy::setCorrelationID(const XMLCh* correlationID)
+{
+ m_correlationID.erase();
+ if (correlationID)
+ m_correlationID = correlationID;
+}
+
void SecurityPolicy::evaluate(const XMLObject& message, const GenericRequest* request)
{
for (vector<const SecurityPolicyRule*>::const_iterator i=m_rules.begin(); i!=m_rules.end(); ++i)
(*i)->evaluate(message,request,*this);
}
+void SecurityPolicy::reset(bool messageOnly)
+{
+ _reset(messageOnly);
+}
+
+void SecurityPolicy::_reset(bool messageOnly)
+{
+ m_messageID.erase();
+ m_issueInstant=0;
+ if (!messageOnly) {
+ delete m_issuer;
+ m_issuer=nullptr;
+ m_issuerRole=nullptr;
+ m_authenticated=false;
+ }
+}
+
+const XMLCh* SecurityPolicy::getMessageID() const
+{
+ return m_messageID.c_str();
+}
+
+time_t SecurityPolicy::getIssueInstant() const
+{
+ return m_issueInstant;
+}
+
+const Issuer* SecurityPolicy::getIssuer() const
+{
+ return m_issuer;
+}
+
+const RoleDescriptor* SecurityPolicy::getIssuerMetadata() const
+{
+ return m_issuerRole;
+}
+
+bool SecurityPolicy::isAuthenticated() const
+{
+ return m_authenticated;
+}
+
+void SecurityPolicy::setMessageID(const XMLCh* id)
+{
+ m_messageID.erase();
+ if (id)
+ m_messageID = id;
+}
+
+void SecurityPolicy::setIssueInstant(time_t issueInstant)
+{
+ m_issueInstant = issueInstant;
+}
+
void SecurityPolicy::setIssuer(const Issuer* issuer)
{
if (!getIssuerMatchingPolicy().issuerMatches(m_issuer, issuer))
if (!m_issuer) {
if (m_entityOnly && issuer->getFormat() && !XMLString::equals(issuer->getFormat(), NameIDType::ENTITY))
throw SecurityPolicyException("A non-entity Issuer was supplied, violating policy.");
- m_issuerRole = NULL;
+ m_issuerRole = nullptr;
m_issuer=issuer->cloneIssuer();
}
}
throw SecurityPolicyException("An Issuer was supplied that conflicts with previous results.");
if (!m_issuer && issuer && *issuer) {
- m_issuerRole = NULL;
+ m_issuerRole = nullptr;
m_issuer = IssuerBuilder::buildIssuer();
m_issuer->setName(issuer);
}
m_issuerRole=issuerRole;
}
+void SecurityPolicy::setAuthenticated(bool auth)
+{
+ m_authenticated = auth;
+}
+
+SecurityPolicy::IssuerMatchingPolicy::IssuerMatchingPolicy()
+{
+}
+
+SecurityPolicy::IssuerMatchingPolicy::~IssuerMatchingPolicy()
+{
+}
+
bool SecurityPolicy::IssuerMatchingPolicy::issuerMatches(const Issuer* issuer1, const Issuer* issuer2) const
{
- // NULL matches anything for the purposes of this interface.
+ // nullptr matches anything for the purposes of this interface.
if (!issuer1 || !issuer2)
return true;
bool SecurityPolicy::IssuerMatchingPolicy::issuerMatches(const Issuer* issuer1, const XMLCh* issuer2) const
{
- // NULL matches anything for the purposes of this interface.
+ // nullptr matches anything for the purposes of this interface.
if (!issuer1 || !issuer2 || !*issuer2)
return true;
return true;
}
+
+SecurityPolicy::IssuerMatchingPolicy SecurityPolicy::m_defaultMatching;
+
+const SecurityPolicy::IssuerMatchingPolicy& SecurityPolicy::getIssuerMatchingPolicy() const
+{
+ return m_matchingPolicy ? *m_matchingPolicy : m_defaultMatching;
+}
+
+void SecurityPolicy::setIssuerMatchingPolicy(IssuerMatchingPolicy* matchingPolicy)
+{
+ delete m_matchingPolicy;
+ m_matchingPolicy = matchingPolicy;
+}