Class: Devise::SamlSessionsController

Inherits:
SessionsController
  • Object
show all
Includes:
DeviseSamlAuthenticatable::SamlConfig
Defined in:
app/controllers/devise/saml_sessions_controller.rb

Instance Method Summary collapse

Methods included from DeviseSamlAuthenticatable::SamlConfig

#saml_config

Instance Method Details

#idp_sign_outObject



24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
# File 'app/controllers/devise/saml_sessions_controller.rb', line 24

def idp_sign_out
  if params[:SAMLRequest] && Devise.saml_session_index_key
    Devise.sign_out_all_scopes ? sign_out : sign_out(resource_name)
    session[Devise.saml_session_index_key] = nil

    saml_config = saml_config(get_idp_entity_id(params), request)
    logout_request = OneLogin::RubySaml::SloLogoutrequest.new(params[:SAMLRequest], settings: saml_config)
    redirect_to generate_idp_logout_response(saml_config, logout_request.id), allow_other_host: true
  elsif params[:SAMLResponse]
    # Currently Devise handles the session invalidation when the request is made.
    # To support a true SP initiated logout response, the request ID would have to be tracked and session invalidated
    # based on that.
    if Devise.saml_sign_out_success_url
      redirect_to Devise.saml_sign_out_success_url
    else
      redirect_to action: :new
    end
  else
    head 500
  end
end

#metadataObject



18
19
20
21
22
# File 'app/controllers/devise/saml_sessions_controller.rb', line 18

def 
  idp_entity_id = params[:idp_entity_id]
  meta = OneLogin::RubySaml::.new
  render xml: meta.generate(saml_config(idp_entity_id, request))
end

#newObject



9
10
11
12
13
14
15
16
# File 'app/controllers/devise/saml_sessions_controller.rb', line 9

def new
  idp_entity_id = get_idp_entity_id(params)
  auth_request = OneLogin::RubySaml::Authrequest.new
  auth_params = { RelayState: relay_state } if relay_state
  action = auth_request.create(saml_config(idp_entity_id, request), auth_params || {})
  session[:saml_transaction_id] = auth_request.request_id if auth_request.respond_to?(:request_id)
  redirect_to action, allow_other_host: true
end