Class: Saml::Kit::Response

Inherits:
Document show all
Includes:
Respondable
Defined in:
lib/saml/kit/response.rb

Constant Summary

Constants inherited from Document

Document::PROTOCOL_XSD

Instance Attribute Summary

Attributes included from Respondable

#request_id

Attributes inherited from Document

#content, #name

Instance Method Summary collapse

Methods included from Respondable

#in_response_to, #query_string_parameter, #status_code, #success?

Methods inherited from Document

builder_class, #destination, #expected_type?, #id, #issue_instant, #issuer, #to_h, #to_s, to_saml_document, #to_xhtml, #to_xml, #version

Methods included from Trustable

#fingerprint, #provider, #signature_verified!, #trusted?

Methods included from XsdValidatable

#error_message, #matches_xsd?

Constructor Details

#initialize(xml, request_id: nil) ⇒ Response

Returns a new instance of Response.



9
10
11
12
# File 'lib/saml/kit/response.rb', line 9

def initialize(xml, request_id: nil)
  @request_id = request_id
  super(xml, name: "Response")
end

Instance Method Details

#[](key) ⇒ Object



18
19
20
# File 'lib/saml/kit/response.rb', line 18

def [](key)
  attributes[key]
end

#active? ⇒ Boolean

Returns:

  • (Boolean)


47
48
49
# File 'lib/saml/kit/response.rb', line 47

def active?
  Time.current > started_at && !expired?
end

#assertion ⇒ Object



55
56
57
58
59
60
61
62
63
64
65
66
# File 'lib/saml/kit/response.rb', line 55

def assertion
  @assertion =
    begin
      if encrypted?
        decrypted = XmlDecryption.new.decrypt(to_h.fetch(name, {}).fetch('EncryptedAssertion', {}))
        Saml::Kit.logger.debug(decrypted)
        Hash.from_xml(decrypted)['Assertion']
      else
        to_h.fetch(name, {}).fetch('Assertion', {})
      end
    end
end

#attributes ⇒ Object



22
23
24
25
26
27
28
29
30
31
32
33
# File 'lib/saml/kit/response.rb', line 22

def attributes
  @attributes ||=
    begin
      attrs = assertion.fetch('AttributeStatement', {}).fetch('Attribute', [])
      items = if attrs.is_a? Hash
        [[attrs["Name"], attrs["AttributeValue"]]]
      else
        attrs.map { |item| [item['Name'], item['AttributeValue']] }
      end
      Hash[items].with_indifferent_access
    end
end

#certificate ⇒ Object



72
73
74
# File 'lib/saml/kit/response.rb', line 72

def certificate
  super || assertion.fetch('Signature', {}).fetch('KeyInfo', {}).fetch('X509Data', {}).fetch('X509Certificate', nil)
end

#encrypted? ⇒ Boolean

Returns:

  • (Boolean)


51
52
53
# File 'lib/saml/kit/response.rb', line 51

def encrypted?
  to_h[name]['EncryptedAssertion'].present?
end

#expired? ⇒ Boolean

Returns:

  • (Boolean)


43
44
45
# File 'lib/saml/kit/response.rb', line 43

def expired?
  Time.current > expired_at
end

#expired_at ⇒ Object



39
40
41
# File 'lib/saml/kit/response.rb', line 39

def expired_at
  parse_date(assertion.fetch('Conditions', {}).fetch('NotOnOrAfter', nil))
end

#name_id ⇒ Object



14
15
16
# File 'lib/saml/kit/response.rb', line 14

def name_id
  assertion.fetch('Subject', {}).fetch('NameID', nil)
end

#signed? ⇒ Boolean

Returns:

  • (Boolean)


68
69
70
# File 'lib/saml/kit/response.rb', line 68

def signed?
  super || assertion.fetch('Signature', nil).present?
end

#started_at ⇒ Object



35
36
37
# File 'lib/saml/kit/response.rb', line 35

def started_at
  parse_date(assertion.fetch('Conditions', {}).fetch('NotBefore', nil))
end