-/*
- * Copyright 2001-2006 Internet2
- *
- * Licensed under the Apache License, Version 2.0 (the "License");
- * you may not use this file except in compliance with the License.
- * You may obtain a copy of the License at
+/**
+ * Licensed to the University Corporation for Advanced Internet
+ * Development, Inc. (UCAID) under one or more contributor license
+ * agreements. See the NOTICE file distributed with this work for
+ * additional information regarding copyright ownership.
*
- * http://www.apache.org/licenses/LICENSE-2.0
+ * UCAID licenses this file to you under the Apache License,
+ * Version 2.0 (the "License"); you may not use this file except
+ * in compliance with the License. You may obtain a copy of the
+ * License at
*
- * Unless required by applicable law or agreed to in writing, software
- * distributed under the License is distributed on an "AS IS" BASIS,
- * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- * See the License for the specific language governing permissions and
- * limitations under the License.
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND,
+ * either express or implied. See the License for the specific
+ * language governing permissions and limitations under the License.
*/
/**
#include "internal.h"
#include "exceptions.h"
-#include "saml/binding/ArtifactMap.h"
-#include "saml/binding/SAMLArtifact.h"
-#include "saml1/binding/SAML1ArtifactEncoder.h"
+#include "binding/ArtifactMap.h"
+#include "binding/MessageEncoder.h"
+#include "binding/SAMLArtifact.h"
#include "saml1/core/Assertions.h"
+#include "saml1/core/Protocols.h"
+#include "saml2/metadata/Metadata.h"
-#include <log4cpp/Category.hh>
+#include <xmltooling/logging.h>
+#include <xmltooling/XMLToolingConfig.h>
+#include <xmltooling/io/HTTPResponse.h>
#include <xmltooling/util/NDC.h>
+#include <xmltooling/util/URLEncoder.h>
using namespace opensaml::saml1;
using namespace opensaml::saml1p;
+using namespace opensaml::saml2md;
using namespace opensaml;
using namespace xmlsignature;
+using namespace xmltooling::logging;
using namespace xmltooling;
-using namespace log4cpp;
using namespace std;
namespace opensaml {
namespace saml1p {
- MessageEncoder* SAML_DLLLOCAL SAML1ArtifactEncoderFactory(const DOMElement* const & e)
+ class SAML_DLLLOCAL SAML1ArtifactEncoder : public MessageEncoder
+ {
+ public:
+ SAML1ArtifactEncoder() {}
+ virtual ~SAML1ArtifactEncoder() {}
+
+ const XMLCh* getProtocolFamily() const {
+ return samlconstants::SAML11_PROTOCOL_ENUM;
+ }
+
+ long encode(
+ GenericResponse& genericResponse,
+ XMLObject* xmlObject,
+ const char* destination,
+ const EntityDescriptor* recipient=nullptr,
+ const char* relayState=nullptr,
+ const ArtifactGenerator* artifactGenerator=nullptr,
+ const Credential* credential=nullptr,
+ const XMLCh* signatureAlg=nullptr,
+ const XMLCh* digestAlg=nullptr
+ ) const;
+ };
+
+ MessageEncoder* SAML_DLLLOCAL SAML1ArtifactEncoderFactory(const pair<const DOMElement*,const XMLCh*>& p)
{
- return new SAML1ArtifactEncoder(e);
+ return new SAML1ArtifactEncoder();
}
};
};
-SAML1ArtifactEncoder::SAML1ArtifactEncoder(const DOMElement* e) {}
-
-SAML1ArtifactEncoder::~SAML1ArtifactEncoder() {}
-
-void SAML1ArtifactEncoder::encode(
- map<string,string>& outputFields,
+long SAML1ArtifactEncoder::encode(
+ GenericResponse& genericResponse,
XMLObject* xmlObject,
- const char* recipientID,
+ const char* destination,
+ const EntityDescriptor* recipient,
const char* relayState,
- const CredentialResolver* credResolver,
- const XMLCh* sigAlgorithm
+ const ArtifactGenerator* artifactGenerator,
+ const Credential* credential,
+ const XMLCh* signatureAlg,
+ const XMLCh* digestAlg
) const
{
#ifdef _DEBUG
xmltooling::NDC ndc("encode");
#endif
- Category& log = Category::getInstance(SAML_LOGCAT".MessageEncoder.SAML1Artifact");
+ Category& log = Category::getInstance(SAML_LOGCAT ".MessageEncoder.SAML1Artifact");
+
log.debug("validating input");
-
- outputFields.clear();
+ HTTPResponse* httpResponse=dynamic_cast<HTTPResponse*>(&genericResponse);
+ if (!httpResponse)
+ throw BindingException("Unable to cast response interface to HTTPResponse type.");
if (xmlObject->getParent())
throw BindingException("Cannot encode XML content with parent.");
Assertion* assertion = dynamic_cast<Assertion*>(xmlObject);
throw BindingException("SAML 1.x Artifact Encoder requires ArtifactMap be set in configuration.");
// Obtain a fresh artifact.
- if (!m_artifactGenerator)
+ if (!artifactGenerator)
throw BindingException("SAML 1.x Artifact Encoder requires an ArtifactGenerator instance.");
- log.debug("obtaining new artifact for relying party (%s)", recipientID ? recipientID : "unknown");
- auto_ptr<SAMLArtifact> artifact(m_artifactGenerator->generateSAML1Artifact(recipientID));
- // Pass back output fields.
- outputFields["SAMLart"] = artifact->encode();
- outputFields["TARGET"] = relayState;
-
+ if (log.isDebugEnabled())
+ log.debugStream() << "marshalled assertion:" << logging::eol << *xmlObject << logging::eol;
+
+ auto_ptr_char recipientID(recipient ? recipient->getEntityID() : nullptr);
+ log.debug("obtaining new artifact for relying party (%s)", recipientID.get() ? recipientID.get() : "unknown");
+ auto_ptr<SAMLArtifact> artifact(artifactGenerator->generateSAML1Artifact(recipient));
+
// Store the assertion. Last step in storage will be to delete the XML.
log.debug("storing artifact and content in map");
- mapper->storeContent(xmlObject, artifact.get(), recipientID);
+ mapper->storeContent(xmlObject, artifact.get(), recipientID.get());
- log.debug("message encoded");
+ // Generate redirect.
+ string loc = destination;
+ loc += (strchr(destination,'?') ? '&' : '?');
+ const URLEncoder* escaper = XMLToolingConfig::getConfig().getURLEncoder();
+ loc = loc + "SAMLart=" + escaper->encode(artifact->encode().c_str()) + "&TARGET=" + escaper->encode(relayState);
+ log.debug("message encoded, sending redirect to client");
+ return httpResponse->sendRedirect(loc.c_str());
}