2 * Copyright 2001-2007 Internet2
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
20 * Tool to exercise SP attribute subsystems.
23 #if defined (_MSC_VER) || defined(__BORLANDC__)
24 # include "config_win32.h"
30 # define _CRT_NONSTDC_NO_DEPRECATE 1
31 # define _CRT_SECURE_NO_DEPRECATE 1
34 #include <shibsp/Application.h>
35 #include <shibsp/exceptions.h>
36 #include <shibsp/SPConfig.h>
37 #include <shibsp/ServiceProvider.h>
38 #include <shibsp/attribute/Attribute.h>
39 #include <shibsp/attribute/resolver/ResolutionContext.h>
40 #include <shibsp/handler/AssertionConsumerService.h>
41 #include <shibsp/util/SPConstants.h>
43 #include <saml/saml1/core/Assertions.h>
44 #include <saml/saml2/core/Assertions.h>
45 #include <saml/saml2/metadata/Metadata.h>
46 #include <xercesc/util/XMLUniDefs.hpp>
47 #include <xmltooling/XMLToolingConfig.h>
48 #include <xmltooling/util/XMLHelper.h>
50 using namespace shibsp;
51 using namespace opensaml::saml2md;
52 using namespace opensaml;
53 using namespace xmltooling::logging;
54 using namespace xmltooling;
55 using namespace xercesc;
58 #if defined (_MSC_VER)
59 #pragma warning( push )
60 #pragma warning( disable : 4250 )
63 class ResolverTest : public shibsp::AssertionConsumerService
66 ResolverTest(const DOMElement* e, const char* appId)
67 : shibsp::AssertionConsumerService(e, appId, Category::getInstance(SHIBSP_LOGCAT".Utilities.ResolverTest")) {
69 virtual ~ResolverTest() {}
71 ResolutionContext* resolveAttributes (
72 const Application& application,
73 const RoleDescriptor* issuer,
74 const XMLCh* protocol,
75 const saml1::NameIdentifier* v1nameid,
76 const saml2::NameID* nameid,
77 const XMLCh* authncontext_class,
78 const XMLCh* authncontext_decl,
79 const vector<const Assertion*>* tokens
81 return shibsp::AssertionConsumerService::resolveAttributes(
82 application, issuer, protocol, v1nameid, nameid, authncontext_class, authncontext_decl, tokens
87 void implementProtocol(
88 const Application& application,
89 const HTTPRequest& httpRequest,
90 HTTPResponse& httpResponse,
91 SecurityPolicy& policy,
92 const PropertySet* settings,
93 const XMLObject& xmlObject
95 throw FatalProfileException("Should never be called.");
99 #if defined (_MSC_VER)
100 #pragma warning( pop )
105 cerr << "usage: resolvertest -n <name> -i <IdP> -p <protocol> [-f <format URI> -a <application id>]" << endl;
106 cerr << " resolvertest [-a <application id>] < assertion.xml" << endl;
109 int main(int argc,char* argv[])
116 const XMLCh* protocol = NULL;
120 for (int i=1; i<argc; i++) {
121 if (!strcmp(argv[i],"-n") && i+1<argc)
123 else if (!strcmp(argv[i],"-f") && i+1<argc)
125 else if (!strcmp(argv[i],"-i") && i+1<argc)
127 else if (!strcmp(argv[i],"-p") && i+1<argc)
129 else if (!strcmp(argv[i],"-saml10"))
130 protocol=samlconstants::SAML10_PROTOCOL_ENUM;
131 else if (!strcmp(argv[i],"-saml11"))
132 protocol=samlconstants::SAML11_PROTOCOL_ENUM;
133 else if (!strcmp(argv[i],"-saml2"))
134 protocol=samlconstants::SAML20P_NS;
135 else if (!strcmp(argv[i],"-a") && i+1<argc)
139 if (n_param && !i_param) {
144 path=getenv("SHIBSP_SCHEMAS");
147 config=getenv("SHIBSP_CONFIG");
149 config=SHIBSP_CONFIG;
153 XMLToolingConfig::getConfig().log_config(getenv("SHIBSP_LOGGING") ? getenv("SHIBSP_LOGGING") : SHIBSP_LOGGING);
155 SPConfig& conf=SPConfig::getConfig();
159 SPConfig::AttributeResolution |
160 SPConfig::Credentials |
161 SPConfig::OutOfProcess
163 if (!conf.init(path))
169 protocol = XMLString::transcode(prot);
179 static const XMLCh path[] = UNICODE_LITERAL_4(p,a,t,h);
180 static const XMLCh validate[] = UNICODE_LITERAL_8(v,a,l,i,d,a,t,e);
181 xercesc::DOMDocument* dummydoc=XMLToolingConfig::getConfig().getParser().newDocument();
182 XercesJanitor<xercesc::DOMDocument> docjanitor(dummydoc);
183 xercesc::DOMElement* dummy = dummydoc->createElementNS(NULL,path);
184 auto_ptr_XMLCh src(config);
185 dummy->setAttributeNS(NULL,path,src.get());
186 dummy->setAttributeNS(NULL,validate,xmlconstants::XML_ONE);
188 conf.setServiceProvider(conf.ServiceProviderManager.newPlugin(XML_SERVICE_PROVIDER,dummy));
189 conf.getServiceProvider()->init();
196 ServiceProvider* sp=conf.getServiceProvider();
199 Category& log = Category::getInstance(SHIBSP_LOGCAT".Utility.ResolverTest");
201 const Application* app = sp->getApplication(a_param);
203 log.error("unknown application ID (%s)", a_param);
210 ResolutionContext* ctx;
213 auto_ptr_XMLCh issuer(i_param);
214 auto_ptr_XMLCh name(n_param);
215 auto_ptr_XMLCh format(f_param);
217 MetadataProvider* m=app->getMetadataProvider();
218 xmltooling::Locker mlocker(m);
219 MetadataProvider::Criteria mc(i_param, &IDPSSODescriptor::ELEMENT_QNAME, protocol);
220 pair<const EntityDescriptor*,const RoleDescriptor*> site=m->getEntityDescriptor(mc);
222 throw MetadataException("Unable to locate metadata for IdP ($1).", params(1,i_param));
225 auto_ptr<saml2::NameID> v2name(saml2::NameIDBuilder::buildNameID());
226 v2name->setName(name.get());
227 v2name->setFormat(format.get());
228 saml1::NameIdentifier* v1name = NULL;
229 if (!XMLString::equals(protocol, samlconstants::SAML20P_NS)) {
230 v1name = saml1::NameIdentifierBuilder::buildNameIdentifier();
231 v1name->setName(name.get());
232 v1name->setFormat(format.get());
233 v1name->setNameQualifier(issuer.get());
236 ResolverTest rt(NULL, a_param);
238 ctx = rt.resolveAttributes(*app, site.second, protocol, v1name, v2name.get(), NULL, NULL, NULL);
246 // Try and load assertion from stdin.
247 DOMDocument* doc = XMLToolingConfig::getConfig().getParser().parse(cin);
248 XercesJanitor<DOMDocument> docjan(doc);
249 auto_ptr<XMLObject> token(XMLObjectBuilder::buildOneFromElement(doc->getDocumentElement(), true));
252 // Get the issuer and protocol and NameIDs.
253 const XMLCh* issuer = NULL;
254 const saml1::NameIdentifier* v1name = NULL;
255 saml2::NameID* v2name = NULL;
256 saml2::Assertion* a2 = dynamic_cast<saml2::Assertion*>(token.get());
257 saml1::Assertion* a1 = dynamic_cast<saml1::Assertion*>(token.get());
259 const saml2::Issuer* iss = a2->getIssuer();
260 issuer = iss ? iss->getName() : NULL;
261 protocol = samlconstants::SAML20P_NS;
262 v2name = a2->getSubject() ? a2->getSubject()->getNameID() : NULL;
265 issuer = a1->getIssuer();
266 if (a1->getMinorVersion().first && a1->getMinorVersion().second == 0)
267 protocol = samlconstants::SAML10_PROTOCOL_ENUM;
269 protocol = samlconstants::SAML11_PROTOCOL_ENUM;
270 v1name = a1->getAuthenticationStatements().size() ?
271 a1->getAuthenticationStatements().front()->getSubject()->getNameIdentifier() : NULL;
272 // Normalize the SAML 1.x NameIdentifier...
273 v2name = saml2::NameIDBuilder::buildNameID();
274 v2name->setName(v1name->getName());
275 v2name->setFormat(v1name->getFormat());
276 v2name->setNameQualifier(v1name->getNameQualifier());
279 throw FatalProfileException("Unknown assertion type.");
285 throw FatalProfileException("Unable to determine issuer.");
288 MetadataProvider* m=app->getMetadataProvider();
289 xmltooling::Locker mlocker(m);
290 MetadataProvider::Criteria mc(issuer, &IDPSSODescriptor::ELEMENT_QNAME, protocol);
291 pair<const EntityDescriptor*,const RoleDescriptor*> site=m->getEntityDescriptor(mc);
293 auto_ptr_char temp(issuer);
294 throw MetadataException("Unable to locate metadata for IdP ($1).", params(1,temp.get()));
297 vector<const Assertion*> tokens(1, dynamic_cast<Assertion*>(token.get()));
298 ResolverTest rt(NULL, a_param);
300 ctx = rt.resolveAttributes(*app, site.second, protocol, v1name, v2name, NULL, NULL, &tokens);
309 auto_ptr<ResolutionContext> wrapper(ctx);
310 for (vector<Attribute*>::const_iterator a = ctx->getResolvedAttributes().begin(); a != ctx->getResolvedAttributes().end(); ++a) {
312 for (vector<string>::const_iterator s = (*a)->getAliases().begin(); s != (*a)->getAliases().end(); ++s)
313 cout << "ID: " << *s << endl;
314 for (vector<string>::const_iterator s = (*a)->getSerializedValues().begin(); s != (*a)->getSerializedValues().end(); ++s)
315 cout << "Value: " << *s << endl;
319 catch(exception& ex) {
320 log.error(ex.what());