Class: Saml::Kit::Metadata

Inherits:
Object
  • Object
show all
Includes:
ActiveModel::Validations, Buildable, Translatable, XsdValidatable
Defined in:
lib/saml/kit/metadata.rb

Constant Summary collapse

METADATA_XSD =
File.expand_path("./xsd/saml-schema-metadata-2.0.xsd", File.dirname(__FILE__)).freeze

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(name, xml) ⇒ Metadata

Returns a new instance of Metadata.



18
19
20
21
22
# File 'lib/saml/kit/metadata.rb', line 18

def initialize(name, xml)
  @name = name
  @xml = xml
  @hash_algorithm = OpenSSL::Digest::SHA256
end

Instance Attribute Details

#hash_algorithm ⇒ Object

Returns the value of attribute hash_algorithm.



16
17
18
# File 'lib/saml/kit/metadata.rb', line 16

def hash_algorithm
  @hash_algorithm
end

#name ⇒ Object (readonly)

Returns the value of attribute name.



15
16
17
# File 'lib/saml/kit/metadata.rb', line 15

def name
  @name
end

#xml ⇒ Object (readonly)

Returns the value of attribute xml.



15
16
17
# File 'lib/saml/kit/metadata.rb', line 15

def xml
  @xml
end

Class Method Details

.builder_class ⇒ Object



124
125
126
# File 'lib/saml/kit/metadata.rb', line 124

def self.builder_class
  Saml::Kit::Builders::Metadata
end

.from(content) ⇒ Object



112
113
114
115
116
117
118
119
120
121
122
# File 'lib/saml/kit/metadata.rb', line 112

def self.from(content)
  hash = Hash.from_xml(content)
  entity_descriptor = hash["EntityDescriptor"]
  if entity_descriptor.key?("SPSSODescriptor") && entity_descriptor.key?("IDPSSODescriptor")
    Saml::Kit::CompositeMetadata.new(content)
  elsif entity_descriptor.keys.include?("SPSSODescriptor")
    Saml::Kit::ServiceProviderMetadata.new(content)
  elsif entity_descriptor.keys.include?("IDPSSODescriptor")
    Saml::Kit::IdentityProviderMetadata.new(content)
  end
end

Instance Method Details

#certificates ⇒ Object



44
45
46
47
48
49
# File 'lib/saml/kit/metadata.rb', line 44

def certificates
  @certificates ||= document.find_all("/md:EntityDescriptor/md:#{name}/md:KeyDescriptor").map do |item|
    cert = item.at_xpath("./ds:KeyInfo/ds:X509Data/ds:X509Certificate", Xml::NAMESPACES).text
    Certificate.new(cert, use: item.attribute('use').value.to_sym)
  end
end

#contact_person_company ⇒ Object



40
41
42
# File 'lib/saml/kit/metadata.rb', line 40

def contact_person_company
  document.find_by("/md:EntityDescriptor/md:ContactPerson/md:Company").try(:text)
end

#encryption_certificates ⇒ Object



51
52
53
# File 'lib/saml/kit/metadata.rb', line 51

def encryption_certificates
  certificates.find_all(&:encryption?)
end

#entity_id ⇒ Object



24
25
26
# File 'lib/saml/kit/metadata.rb', line 24

def entity_id
  document.find_by("/md:EntityDescriptor/@entityID").value
end

#logout_request_for(user, binding: :http_post, relay_state: nil) ⇒ Object



80
81
82
83
84
85
86
# File 'lib/saml/kit/metadata.rb', line 80

def logout_request_for(user, binding: :http_post, relay_state: nil)
  builder = Saml::Kit::LogoutRequest.builder(user) do |x|
    yield x if block_given?
  end
  request_binding = single_logout_service_for(binding: binding)
  request_binding.serialize(builder, relay_state: relay_state)
end

#matches?(fingerprint, use: :signing) ⇒ Boolean

Returns:

  • (Boolean)


88
89
90
91
92
# File 'lib/saml/kit/metadata.rb', line 88

def matches?(fingerprint, use: :signing)
  certificates.find do |certificate|
    certificate.for?(use) && certificate.fingerprint == fingerprint
  end
end

#name_id_formats ⇒ Object



28
29
30
# File 'lib/saml/kit/metadata.rb', line 28

def name_id_formats
  document.find_all("/md:EntityDescriptor/md:#{name}/md:NameIDFormat").map(&:text)
end

#organization_name ⇒ Object



32
33
34
# File 'lib/saml/kit/metadata.rb', line 32

def organization_name
  document.find_by("/md:EntityDescriptor/md:Organization/md:OrganizationName").try(:text)
end

#organization_url ⇒ Object



36
37
38
# File 'lib/saml/kit/metadata.rb', line 36

def organization_url
  document.find_by("/md:EntityDescriptor/md:Organization/md:OrganizationURL").try(:text)
end

#service_for(binding:, type:) ⇒ Object



67
68
69
70
# File 'lib/saml/kit/metadata.rb', line 67

def service_for(binding:, type:)
  binding = Saml::Kit::Bindings.binding_for(binding)
  services(type).find { |x| x.binding?(binding) }
end

#services(type) ⇒ Object



59
60
61
62
63
64
65
# File 'lib/saml/kit/metadata.rb', line 59

def services(type)
  document.find_all("/md:EntityDescriptor/md:#{name}/md:#{type}").map do |item|
    binding = item.attribute("Binding").value
    location = item.attribute("Location").value
    Saml::Kit::Bindings.create_for(binding, location)
  end
end

#signing_certificates ⇒ Object



55
56
57
# File 'lib/saml/kit/metadata.rb', line 55

def signing_certificates
  certificates.find_all(&:signing?)
end

#single_logout_service_for(binding:) ⇒ Object



76
77
78
# File 'lib/saml/kit/metadata.rb', line 76

def single_logout_service_for(binding:)
  service_for(binding: binding, type: 'SingleLogoutService')
end

#single_logout_services ⇒ Object



72
73
74
# File 'lib/saml/kit/metadata.rb', line 72

def single_logout_services
  services('SingleLogoutService')
end

#to_h ⇒ Object



94
95
96
# File 'lib/saml/kit/metadata.rb', line 94

def to_h
  @xml_hash ||= Hash.from_xml(to_xml)
end

#to_s ⇒ Object



102
103
104
# File 'lib/saml/kit/metadata.rb', line 102

def to_s
  to_xml
end

#to_xml(pretty: false) ⇒ Object



98
99
100
# File 'lib/saml/kit/metadata.rb', line 98

def to_xml(pretty: false)
  document.to_xml(pretty: pretty)
end

#verify(algorithm, signature, data) ⇒ Object



106
107
108
109
110
# File 'lib/saml/kit/metadata.rb', line 106

def verify(algorithm, signature, data)
  signing_certificates.find do |certificate|
    certificate.public_key.verify(algorithm, signature, data)
  end
end