Class: OneLogin::RubySaml::IdpMetadataParser::IdpMetadata

Inherits:
Object
  • Object
show all
Defined in:
lib/onelogin/ruby-saml/idp_metadata_parser.rb

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(idpsso_descriptor, entity_id) ⇒ IdpMetadata

Returns a new instance of IdpMetadata.



226
227
228
229
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 226

def initialize(idpsso_descriptor, entity_id)
  @idpsso_descriptor = idpsso_descriptor
  @entity_id = entity_id
end

Instance Attribute Details

#entity_idObject (readonly)

Returns the value of attribute entity_id.



224
225
226
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 224

def entity_id
  @entity_id
end

#idpsso_descriptorObject (readonly)

Returns the value of attribute idpsso_descriptor.



224
225
226
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 224

def idpsso_descriptor
  @idpsso_descriptor
end

Instance Method Details

#attribute_namesArray

Returns the names of all SAML attributes if any exist.

Returns:

  • (Array)

    the names of all SAML attributes if any exist



399
400
401
402
403
404
405
406
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 399

def attribute_names
  nodes = REXML::XPath.match(
    @idpsso_descriptor  ,
    "saml:Attribute/@Name",
    SamlMetadata::NAMESPACE
  )
  nodes.map(&:value)
end

#cache_durationString|nil

Returns ‘cacheDuration’ attribute of metadata.

Returns:

  • (String|nil)

    ‘cacheDuration’ attribute of metadata



262
263
264
265
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 262

def cache_duration
  root = @idpsso_descriptor.root
  root.attributes['cacheDuration'] if root && root.attributes
end

#certificatesString|nil

Returns Unformatted Certificate if exists.

Returns:

  • (String|nil)

    Unformatted Certificate if exists



350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 350

def certificates
  @certificates ||= begin
    signing_nodes = REXML::XPath.match(
      @idpsso_descriptor,
      "md:KeyDescriptor[not(contains(@use, 'encryption'))]/ds:KeyInfo/ds:X509Data/ds:X509Certificate",
      SamlMetadata::NAMESPACE
    )

    encryption_nodes = REXML::XPath.match(
      @idpsso_descriptor,
      "md:KeyDescriptor[not(contains(@use, 'signing'))]/ds:KeyInfo/ds:X509Data/ds:X509Certificate",
      SamlMetadata::NAMESPACE
    )

    return nil if signing_nodes.empty? && encryption_nodes.empty?

    certs = {}
    unless signing_nodes.empty?
      certs['signing'] = []
      signing_nodes.each do |cert_node|
        certs['signing'] << Utils.element_text(cert_node)
      end
    end

    unless encryption_nodes.empty?
      certs['encryption'] = []
      encryption_nodes.each do |cert_node|
        certs['encryption'] << Utils.element_text(cert_node)
      end
    end
    certs
  end
end

#certificates_has_one(key) ⇒ Object



433
434
435
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 433

def certificates_has_one(key)
  certificates.key?(key) && certificates[key].size == 1
end

#fingerprint(certificate, fingerprint_algorithm = XMLSecurity::Document::SHA1) ⇒ String|nil

Returns the fingerpint of the X509Certificate if it exists.

Returns:

  • (String|nil)

    the fingerpint of the X509Certificate if it exists



386
387
388
389
390
391
392
393
394
395
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 386

def fingerprint(certificate, fingerprint_algorithm = XMLSecurity::Document::SHA1)
  @fingerprint ||= begin
    return unless certificate

    cert = OpenSSL::X509::Certificate.new(Base64.decode64(certificate))

    fingerprint_alg = XMLSecurity::BaseDocument.new.algorithm(fingerprint_algorithm).new
    fingerprint_alg.hexdigest(cert.to_der).upcase.scan(/../).join(":")
  end
end

#idp_name_id_format(name_id_priority = nil) ⇒ String|nil

Returns IdP NameIDFormat value if exists.

Parameters:

  • name_id_priority (String|Array<String>) (defaults to: nil)

    The prioritized list of NameIDFormat values to select. Will select first value if nil.

Returns:

  • (String|nil)

    IdP NameIDFormat value if exists



270
271
272
273
274
275
276
277
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 270

def idp_name_id_format(name_id_priority = nil)
  nodes = REXML::XPath.match(
    @idpsso_descriptor,
    "md:NameIDFormat",
    SamlMetadata::NAMESPACE
  )
  first_ranked_text(nodes, name_id_priority)
end

#merge_certificates_into(parsed_metadata) ⇒ Object



408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 408

def merge_certificates_into()
  if (certificates.size == 1 &&
      (certificates_has_one('signing') || certificates_has_one('encryption'))) ||
      (certificates_has_one('signing') && certificates_has_one('encryption') &&
      certificates["signing"][0] == certificates["encryption"][0])

    if certificates.key?("signing")
      [:idp_cert] = certificates["signing"][0]
      [:idp_cert_fingerprint] = fingerprint(
        [:idp_cert],
        [:idp_cert_fingerprint_algorithm]
      )
    else
      [:idp_cert] = certificates["encryption"][0]
      [:idp_cert_fingerprint] = fingerprint(
        [:idp_cert],
        [:idp_cert_fingerprint_algorithm]
      )
    end
  end

  # symbolize keys of certificates and pass it on
  [:idp_cert_multi] = Hash[certificates.map { |k, v| [k.to_sym, v] }]
end

#single_logout_response_service_url(binding_priority = nil) ⇒ String|nil

Returns SingleLogoutService response url if exists.

Parameters:

  • binding_priority (String|Array<String>) (defaults to: nil)

    The prioritized list of Binding values to select. Will select first value if nil.

Returns:

  • (String|nil)

    SingleLogoutService response url if exists



336
337
338
339
340
341
342
343
344
345
346
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 336

def single_logout_response_service_url(binding_priority = nil)
  binding = single_logout_service_binding(binding_priority)
  return if binding.nil?

  node = REXML::XPath.first(
    @idpsso_descriptor,
    "md:SingleLogoutService[@Binding=\"#{binding}\"]/@ResponseLocation",
    SamlMetadata::NAMESPACE
  )
  node.value if node
end

#single_logout_service_binding(binding_priority = nil) ⇒ String|nil

Returns SingleLogoutService binding if exists.

Parameters:

  • binding_priority (String|Array<String>) (defaults to: nil)

    The prioritized list of Binding values to select. Will select first value if nil.

Returns:

  • (String|nil)

    SingleLogoutService binding if exists



294
295
296
297
298
299
300
301
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 294

def single_logout_service_binding(binding_priority = nil)
  nodes = REXML::XPath.match(
    @idpsso_descriptor,
    "md:SingleLogoutService/@Binding",
    SamlMetadata::NAMESPACE
  )
  first_ranked_value(nodes, binding_priority)
end

#single_logout_service_url(binding_priority = nil) ⇒ String|nil

Returns SingleLogoutService endpoint if exists.

Parameters:

  • binding_priority (String|Array<String>) (defaults to: nil)

    The prioritized list of Binding values to select. Will select first value if nil.

Returns:

  • (String|nil)

    SingleLogoutService endpoint if exists



321
322
323
324
325
326
327
328
329
330
331
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 321

def single_logout_service_url(binding_priority = nil)
  binding = single_logout_service_binding(binding_priority)
  return if binding.nil?

  node = REXML::XPath.first(
    @idpsso_descriptor,
    "md:SingleLogoutService[@Binding=\"#{binding}\"]/@Location",
    SamlMetadata::NAMESPACE
  )
  node.value if node
end

#single_signon_service_binding(binding_priority = nil) ⇒ String|nil

Returns SingleSignOnService binding if exists.

Parameters:

  • binding_priority (String|Array<String>) (defaults to: nil)

    The prioritized list of Binding values to select. Will select first value if nil.

Returns:

  • (String|nil)

    SingleSignOnService binding if exists



282
283
284
285
286
287
288
289
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 282

def single_signon_service_binding(binding_priority = nil)
  nodes = REXML::XPath.match(
    @idpsso_descriptor,
    "md:SingleSignOnService/@Binding",
    SamlMetadata::NAMESPACE
  )
  first_ranked_value(nodes, binding_priority)
end

#single_signon_service_url(binding_priority = nil) ⇒ String|nil

Returns SingleSignOnService endpoint if exists.

Parameters:

  • binding_priority (String|Array<String>) (defaults to: nil)

    The prioritized list of Binding values to select. Will select first value if nil.

Returns:

  • (String|nil)

    SingleSignOnService endpoint if exists



306
307
308
309
310
311
312
313
314
315
316
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 306

def single_signon_service_url(binding_priority = nil)
  binding = single_signon_service_binding(binding_priority)
  return if binding.nil?

  node = REXML::XPath.first(
    @idpsso_descriptor,
    "md:SingleSignOnService[@Binding=\"#{binding}\"]/@Location",
    SamlMetadata::NAMESPACE
  )
  node.value if node
end

#to_hash(options = {}) ⇒ Object



231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 231

def to_hash(options = {})
  sso_binding = options[:sso_binding]
  slo_binding = options[:slo_binding]
  {
    :idp_entity_id => @entity_id,
    :name_identifier_format => idp_name_id_format(options[:name_id_format]),
    :idp_sso_service_url => single_signon_service_url(sso_binding),
    :idp_sso_service_binding => single_signon_service_binding(sso_binding),
    :idp_slo_service_url => single_logout_service_url(slo_binding),
    :idp_slo_service_binding => single_logout_service_binding(slo_binding),
    :idp_slo_response_service_url => single_logout_response_service_url(slo_binding),
    :idp_attribute_names => attribute_names,
    :idp_cert => nil,
    :idp_cert_fingerprint => nil,
    :idp_cert_multi => nil,
    :valid_until => valid_until,
    :cache_duration => cache_duration,
  }.tap do |response_hash|
    merge_certificates_into(response_hash) unless certificates.nil?
  end
end

#valid_untilString|nil

Returns ‘validUntil’ attribute of metadata.

Returns:

  • (String|nil)

    ‘validUntil’ attribute of metadata



255
256
257
258
# File 'lib/onelogin/ruby-saml/idp_metadata_parser.rb', line 255

def valid_until
  root = @idpsso_descriptor.root
  root.attributes['validUntil'] if root && root.attributes
end