Class: Saml::Kit::Configuration
- Inherits:
-
Object
- Object
- Saml::Kit::Configuration
- Defined in:
- lib/saml/kit/configuration.rb
Overview
This class represents the main configuration that is use for generating SAML documents.
Saml::Kit::Configuration.new do |config|
config.issuer = "com:saml:kit"
config.signature_method = :SHA256
config.digest_method = :SHA256
config.registry = Saml::Kit::DefaultRegistry.new
config.session_timeout = 30.minutes
config.logger = Rails.logger
end
To specify global configuration it is best to do this in an initialize
that runs at the start of the program.
Saml::Kit.configure do |configuration|
configuration.issuer = "https://www.example.com/saml/metadata"
configuration.generate_key_pair_for(use: :signing)
configuration.add_key_pair(ENV["X509_CERTIFICATE"], ENV["PRIVATE_KEY"], password: ENV['PRIVATE_KEY_PASSWORD'], use: :encryption)
end
Instance Attribute Summary collapse
-
#digest_method ⇒ Object
The digest method to use when generating signatures (See SAML::Kit::Builders::XmlSignature::DIGEST_METHODS).
-
#issuer ⇒ Object
The issuer or entity_id to use.
-
#logger ⇒ Object
The logger to write log messages to.
-
#registry ⇒ Object
The metadata registry to use for searching for metadata associated with an issuer.
-
#session_timeout ⇒ Object
The session timeout to use when generating an Assertion.
-
#signature_method ⇒ Object
The signature method to use when generating signatures (See SAML::Kit::Builders::XmlSignature::SIGNATURE_METHODS).
Instance Method Summary collapse
-
#add_key_pair(certificate, private_key, password: '', use: :signing) ⇒ Object
Add a key pair that can be used for either signing or encryption.
-
#certificates(use: nil) ⇒ Object
Return each certificate for a specific use.
-
#encryption_certificate ⇒ Object
deprecated
Deprecated.
Use #certificates instead of this method.
-
#encryption_private_key ⇒ Object
deprecated
Deprecated.
Use #private_keys instead of this method.
-
#generate_key_pair_for(use:, password: SecureRandom.uuid) ⇒ Object
Generates a unique key pair that can be used for signing or encryption.
-
#initialize {|_self| ... } ⇒ Configuration
constructor
:yields configuration.
-
#key_pairs(use: nil) ⇒ Object
Return each key pair for a specific use.
-
#private_keys(use: :signing) ⇒ Object
Return each private for a specific use.
-
#sign? ⇒ Boolean
Returns true if there is at least one signing certificate registered.
-
#signing_private_key ⇒ Object
deprecated
Deprecated.
Use #private_keys instead of this method.
Constructor Details
#initialize {|_self| ... } ⇒ Configuration
:yields configuration
36 37 38 39 40 41 42 43 44 |
# File 'lib/saml/kit/configuration.rb', line 36 def initialize # :yields configuration @signature_method = :SHA256 @digest_method = :SHA256 @registry = DefaultRegistry.new @session_timeout = 3.hours @logger = Logger.new(STDOUT) @key_pairs = [] yield self if block_given? end |
Instance Attribute Details
#digest_method ⇒ Object
The digest method to use when generating signatures (See SAML::Kit::Builders::XmlSignature::DIGEST_METHODS)
28 29 30 |
# File 'lib/saml/kit/configuration.rb', line 28 def digest_method @digest_method end |
#issuer ⇒ Object
The issuer or entity_id to use.
24 25 26 |
# File 'lib/saml/kit/configuration.rb', line 24 def issuer @issuer end |
#logger ⇒ Object
The logger to write log messages to.
34 35 36 |
# File 'lib/saml/kit/configuration.rb', line 34 def logger @logger end |
#registry ⇒ Object
The metadata registry to use for searching for metadata associated with an issuer.
30 31 32 |
# File 'lib/saml/kit/configuration.rb', line 30 def registry @registry end |
#session_timeout ⇒ Object
The session timeout to use when generating an Assertion.
32 33 34 |
# File 'lib/saml/kit/configuration.rb', line 32 def session_timeout @session_timeout end |
#signature_method ⇒ Object
The signature method to use when generating signatures (See SAML::Kit::Builders::XmlSignature::SIGNATURE_METHODS)
26 27 28 |
# File 'lib/saml/kit/configuration.rb', line 26 def signature_method @signature_method end |
Instance Method Details
#add_key_pair(certificate, private_key, password: '', use: :signing) ⇒ Object
Add a key pair that can be used for either signing or encryption.
52 53 54 |
# File 'lib/saml/kit/configuration.rb', line 52 def add_key_pair(certificate, private_key, password: '', use: :signing) @key_pairs.push(KeyPair.new(certificate, private_key, password, use.to_sym)) end |
#certificates(use: nil) ⇒ Object
Return each certificate for a specific use.
75 76 77 |
# File 'lib/saml/kit/configuration.rb', line 75 def certificates(use: nil) key_pairs(use: use).flat_map(&:certificate) end |
#encryption_certificate ⇒ Object
Use #certificates instead of this method.
87 88 89 90 |
# File 'lib/saml/kit/configuration.rb', line 87 def encryption_certificate Saml::Kit.deprecate("encryption_certificate is deprecated. Use certificates(use: :encryption) instead") certificates(use: :encryption).last end |
#encryption_private_key ⇒ Object
Use #private_keys instead of this method.
99 100 101 102 |
# File 'lib/saml/kit/configuration.rb', line 99 def encryption_private_key Saml::Kit.deprecate("encryption_private_key is deprecated. Use private_keys(use: :encryption) instead") private_keys(use: :encryption).last end |
#generate_key_pair_for(use:, password: SecureRandom.uuid) ⇒ Object
Generates a unique key pair that can be used for signing or encryption.
60 61 62 63 |
# File 'lib/saml/kit/configuration.rb', line 60 def generate_key_pair_for(use:, password: SecureRandom.uuid) certificate, private_key = SelfSignedCertificate.new(password).create add_key_pair(certificate, private_key, password: password, use: use) end |
#key_pairs(use: nil) ⇒ Object
Return each key pair for a specific use.
68 69 70 |
# File 'lib/saml/kit/configuration.rb', line 68 def key_pairs(use: nil) use.present? ? @key_pairs.find_all { |x| x.for?(use) } : @key_pairs end |
#private_keys(use: :signing) ⇒ Object
Return each private for a specific use.
82 83 84 |
# File 'lib/saml/kit/configuration.rb', line 82 def private_keys(use: :signing) key_pairs(use: use).flat_map(&:private_key) end |
#sign? ⇒ Boolean
Returns true if there is at least one signing certificate registered.
105 106 107 |
# File 'lib/saml/kit/configuration.rb', line 105 def sign? certificates(use: :signing).any? end |
#signing_private_key ⇒ Object
Use #private_keys instead of this method.
93 94 95 96 |
# File 'lib/saml/kit/configuration.rb', line 93 def signing_private_key Saml::Kit.deprecate("signing_private_key is deprecated. Use private_keys(use: :signing) instead") private_keys(use: :signing).last end |