Class: Saml::Kit::Metadata
Constant Summary
collapse
- METADATA_XSD =
File.expand_path("./xsd/saml-schema-metadata-2.0.xsd", File.dirname(__FILE__)).freeze
Instance Attribute Summary collapse
Class Method Summary
collapse
Instance Method Summary
collapse
#error_message
#matches_xsd?
Constructor Details
#initialize(name, xml) ⇒ Metadata
Returns a new instance of Metadata.
18
19
20
21
22
|
# File 'lib/saml/kit/metadata.rb', line 18
def initialize(name, xml)
@name = name
@xml = xml
@hash_algorithm = OpenSSL::Digest::SHA256
end
|
Instance Attribute Details
#hash_algorithm ⇒ Object
Returns the value of attribute hash_algorithm.
16
17
18
|
# File 'lib/saml/kit/metadata.rb', line 16
def hash_algorithm
@hash_algorithm
end
|
#name ⇒ Object
Returns the value of attribute name.
15
16
17
|
# File 'lib/saml/kit/metadata.rb', line 15
def name
@name
end
|
#xml ⇒ Object
Returns the value of attribute xml.
15
16
17
|
# File 'lib/saml/kit/metadata.rb', line 15
def xml
@xml
end
|
Class Method Details
.from(content) ⇒ Object
100
101
102
103
104
105
106
107
108
109
110
|
# File 'lib/saml/kit/metadata.rb', line 100
def self.from(content)
hash = Hash.from_xml(content)
entity_descriptor = hash["EntityDescriptor"]
if entity_descriptor.key?("SPSSODescriptor") && entity_descriptor.key?("IDPSSODescriptor")
Saml::Kit::CompositeMetadata.new(content)
elsif entity_descriptor.keys.include?("SPSSODescriptor")
Saml::Kit::ServiceProviderMetadata.new(content)
elsif entity_descriptor.keys.include?("IDPSSODescriptor")
Saml::Kit::IdentityProviderMetadata.new(content)
end
end
|
Instance Method Details
#certificates ⇒ Object
32
33
34
35
36
37
|
# File 'lib/saml/kit/metadata.rb', line 32
def certificates
@certificates ||= document.find_all("/md:EntityDescriptor/md:#{name}/md:KeyDescriptor").map do |item|
cert = item.at_xpath("./ds:KeyInfo/ds:X509Data/ds:X509Certificate", Xml::NAMESPACES).text
Certificate.new(cert, use: item.attribute('use').value.to_sym)
end
end
|
#encryption_certificates ⇒ Object
39
40
41
|
# File 'lib/saml/kit/metadata.rb', line 39
def encryption_certificates
certificates.find_all(&:encryption?)
end
|
#entity_id ⇒ Object
24
25
26
|
# File 'lib/saml/kit/metadata.rb', line 24
def entity_id
document.find_by("/md:EntityDescriptor/@entityID").value
end
|
#logout_request_for(user, binding: :http_post, relay_state: nil) ⇒ Object
68
69
70
71
72
73
74
|
# File 'lib/saml/kit/metadata.rb', line 68
def logout_request_for(user, binding: :http_post, relay_state: nil)
builder = Saml::Kit::LogoutRequest.builder(user) do |x|
yield x if block_given?
end
request_binding = single_logout_service_for(binding: binding)
request_binding.serialize(builder, relay_state: relay_state)
end
|
#matches?(fingerprint, use: :signing) ⇒ Boolean
76
77
78
79
80
|
# File 'lib/saml/kit/metadata.rb', line 76
def matches?(fingerprint, use: :signing)
certificates.find do |certificate|
certificate.for?(use) && certificate.fingerprint == fingerprint
end
end
|
28
29
30
|
# File 'lib/saml/kit/metadata.rb', line 28
def name_id_formats
document.find_all("/md:EntityDescriptor/md:#{name}/md:NameIDFormat").map(&:text)
end
|
#service_for(binding:, type:) ⇒ Object
55
56
57
58
|
# File 'lib/saml/kit/metadata.rb', line 55
def service_for(binding:, type:)
binding = Saml::Kit::Bindings.binding_for(binding)
services(type).find { |x| x.binding?(binding) }
end
|
#services(type) ⇒ Object
47
48
49
50
51
52
53
|
# File 'lib/saml/kit/metadata.rb', line 47
def services(type)
document.find_all("/md:EntityDescriptor/md:#{name}/md:#{type}").map do |item|
binding = item.attribute("Binding").value
location = item.attribute("Location").value
Saml::Kit::Bindings.create_for(binding, location)
end
end
|
#signing_certificates ⇒ Object
43
44
45
|
# File 'lib/saml/kit/metadata.rb', line 43
def signing_certificates
certificates.find_all(&:signing?)
end
|
#single_logout_service_for(binding:) ⇒ Object
64
65
66
|
# File 'lib/saml/kit/metadata.rb', line 64
def single_logout_service_for(binding:)
service_for(binding: binding, type: 'SingleLogoutService')
end
|
#single_logout_services ⇒ Object
60
61
62
|
# File 'lib/saml/kit/metadata.rb', line 60
def single_logout_services
services('SingleLogoutService')
end
|
#to_h ⇒ Object
82
83
84
|
# File 'lib/saml/kit/metadata.rb', line 82
def to_h
@xml_hash ||= Hash.from_xml(to_xml)
end
|
#to_s ⇒ Object
90
91
92
|
# File 'lib/saml/kit/metadata.rb', line 90
def to_s
to_xml
end
|
#to_xml(pretty: false) ⇒ Object
86
87
88
|
# File 'lib/saml/kit/metadata.rb', line 86
def to_xml(pretty: false)
document.to_xml(pretty: pretty)
end
|
#verify(algorithm, signature, data) ⇒ Object
94
95
96
97
98
|
# File 'lib/saml/kit/metadata.rb', line 94
def verify(algorithm, signature, data)
signing_certificates.find do |certificate|
certificate.public_key.verify(algorithm, signature, data)
end
end
|