Class: Saml::Kit::Signature

Inherits:
Object
  • Object
show all
Defined in:
lib/saml/kit/signature.rb

Constant Summary collapse

SIGNATURE_METHODS =
{
  SHA1: "http://www.w3.org/2000/09/xmldsig#rsa-sha1",
  SHA224: "http://www.w3.org/2001/04/xmldsig-more#rsa-sha224",
  SHA256: "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256",
  SHA384: "http://www.w3.org/2001/04/xmldsig-more#rsa-sha384",
  SHA512: "http://www.w3.org/2001/04/xmldsig-more#rsa-sha512",
}.freeze
DIGEST_METHODS =
{
  SHA1: "http://www.w3.org/2000/09/xmldsig#SHA1",
  SHA224: "http://www.w3.org/2001/04/xmldsig-more#sha224",
  SHA256: "http://www.w3.org/2001/04/xmlenc#sha256",
  SHA384: "http://www.w3.org/2001/04/xmldsig-more#sha384",
  SHA512: "http://www.w3.org/2001/04/xmlenc#sha512",
}.freeze

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(xml, configuration:, sign: true) ⇒ Signature

Returns a new instance of Signature.



21
22
23
24
25
26
# File 'lib/saml/kit/signature.rb', line 21

def initialize(xml, configuration:, sign: true)
  @xml = xml
  @configuration = configuration
  @sign = sign
  @reference_ids = []
end

Instance Attribute Details

#configuration ⇒ Object (readonly)

Returns the value of attribute configuration.



19
20
21
# File 'lib/saml/kit/signature.rb', line 19

def configuration
  @configuration
end

#sign ⇒ Object (readonly)

Returns the value of attribute sign.



19
20
21
# File 'lib/saml/kit/signature.rb', line 19

def sign
  @sign
end

#xml ⇒ Object (readonly)

Returns the value of attribute xml.



19
20
21
# File 'lib/saml/kit/signature.rb', line 19

def xml
  @xml
end

Class Method Details

.sign(sign: true, xml: ::Builder::XmlMarkup.new, configuration: Saml::Kit.configuration) {|xml, signature| ... } ⇒ Object

Yields:

  • (xml, signature)


65
66
67
68
69
# File 'lib/saml/kit/signature.rb', line 65

def self.sign(sign: true, xml: ::Builder::XmlMarkup.new, configuration: Saml::Kit.configuration)
  signature = new(xml, sign: sign, configuration: configuration)
  yield xml, signature
  signature.finalize
end

Instance Method Details

#finalize ⇒ Object



55
56
57
58
59
60
61
62
63
# File 'lib/saml/kit/signature.rb', line 55

def finalize
  return xml.target! unless sign

  raw_xml = xml.target!
  @reference_ids.each do |reference_id|
    raw_xml = Xmldsig::SignedDocument.new(raw_xml).sign(private_key)
  end
  raw_xml
end

#template(reference_id) ⇒ Object



28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
# File 'lib/saml/kit/signature.rb', line 28

def template(reference_id)
  return unless sign
  return if reference_id.blank?
  @reference_ids << reference_id

  xml.Signature "xmlns" => Namespaces::XMLDSIG do
    xml.SignedInfo do
      xml.CanonicalizationMethod Algorithm: "http://www.w3.org/2001/10/xml-exc-c14n#"
      xml.SignatureMethod Algorithm: SIGNATURE_METHODS[configuration.signature_method]
      xml.Reference URI: "##{reference_id}" do
        xml.Transforms do
          xml.Transform Algorithm: "http://www.w3.org/2000/09/xmldsig#enveloped-signature"
          xml.Transform Algorithm: "http://www.w3.org/2001/10/xml-exc-c14n#"
        end
        xml.DigestMethod Algorithm: DIGEST_METHODS[configuration.digest_method]
        xml.DigestValue ""
      end
    end
    xml.SignatureValue ""
    xml.KeyInfo do
      xml.X509Data do
        xml.X509Certificate configuration.stripped_signing_certificate
      end
    end
  end
end