Changed origin to use new policy URI.
[java-idp.git] / src / edu / internet2 / middleware / shibboleth / aa / AASaml.java
1 /* 
2  * The Shibboleth License, Version 1. 
3  * Copyright (c) 2002 
4  * University Corporation for Advanced Internet Development, Inc. 
5  * All rights reserved
6  * 
7  * 
8  * Redistribution and use in source and binary forms, with or without 
9  * modification, are permitted provided that the following conditions are met:
10  * 
11  * Redistributions of source code must retain the above copyright notice, this 
12  * list of conditions and the following disclaimer.
13  * 
14  * Redistributions in binary form must reproduce the above copyright notice, 
15  * this list of conditions and the following disclaimer in the documentation 
16  * and/or other materials provided with the distribution, if any, must include 
17  * the following acknowledgment: "This product includes software developed by 
18  * the University Corporation for Advanced Internet Development 
19  * <http://www.ucaid.edu>Internet2 Project. Alternately, this acknowledegement 
20  * may appear in the software itself, if and wherever such third-party 
21  * acknowledgments normally appear.
22  * 
23  * Neither the name of Shibboleth nor the names of its contributors, nor 
24  * Internet2, nor the University Corporation for Advanced Internet Development, 
25  * Inc., nor UCAID may be used to endorse or promote products derived from this 
26  * software without specific prior written permission. For written permission, 
27  * please contact shibboleth@shibboleth.org
28  * 
29  * Products derived from this software may not be called Shibboleth, Internet2, 
30  * UCAID, or the University Corporation for Advanced Internet Development, nor 
31  * may Shibboleth appear in their name, without prior written permission of the 
32  * University Corporation for Advanced Internet Development.
33  * 
34  * 
35  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" 
36  * AND WITH ALL FAULTS. ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 
37  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A 
38  * PARTICULAR PURPOSE, AND NON-INFRINGEMENT ARE DISCLAIMED AND THE ENTIRE RISK 
39  * OF SATISFACTORY QUALITY, PERFORMANCE, ACCURACY, AND EFFORT IS WITH LICENSEE. 
40  * IN NO EVENT SHALL THE COPYRIGHT OWNER, CONTRIBUTORS OR THE UNIVERSITY 
41  * CORPORATION FOR ADVANCED INTERNET DEVELOPMENT, INC. BE LIABLE FOR ANY DIRECT, 
42  * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES 
43  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 
44  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND 
45  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 
46  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS 
47  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
48  */
49
50 package edu.internet2.middleware.shibboleth.aa;
51
52 /**
53  *  Attribute Authority & Release Policy
54  *  SAML Layer for AA
55  *
56  * @author     Parviz Dousti (dousti@cmu.edu)
57  * @created    June, 2002
58  */
59
60
61 import java.io.IOException;
62 import java.util.Arrays;
63 import java.util.Collection;
64 import java.util.Collections;
65 import java.util.Date;
66 import java.util.Iterator;
67
68 import javax.servlet.http.HttpServletRequest;
69 import javax.servlet.http.HttpServletResponse;
70
71 import org.apache.log4j.Logger;
72 import org.opensaml.SAMLAssertion;
73 import org.opensaml.SAMLAttribute;
74 import org.opensaml.SAMLAttributeQuery;
75 import org.opensaml.SAMLAttributeStatement;
76 import org.opensaml.SAMLAudienceRestrictionCondition;
77 import org.opensaml.SAMLBinding;
78 import org.opensaml.SAMLCondition;
79 import org.opensaml.SAMLException;
80 import org.opensaml.SAMLQuery;
81 import org.opensaml.SAMLRequest;
82 import org.opensaml.SAMLResponse;
83 import org.opensaml.SAMLStatement;
84 import org.opensaml.SAMLSubject;
85 import sun.misc.BASE64Decoder;
86
87 import edu.internet2.middleware.shibboleth.common.Constants;
88 import edu.internet2.middleware.shibboleth.common.SAMLBindingFactory;
89
90
91 public class AASaml {
92
93     String[] policies = { Constants.POLICY_INCOMMON };
94     String myName;
95     StringBuffer sharName;
96     SAMLRequest sreq;
97     SAMLAttributeQuery aquery;
98     SAMLBinding binding;
99     private static Logger log = Logger.getLogger(AASaml.class.getName());        
100
101     public AASaml(String myName) throws SAMLException {
102         binding = SAMLBindingFactory.getInstance(SAMLBinding.SAML_SOAP_HTTPS);
103         this.myName = myName;
104     }
105
106     public void receive(HttpServletRequest req) throws SAMLException {
107         sharName=new StringBuffer();
108         sreq = binding.receive(req, sharName);
109         SAMLQuery q = sreq.getQuery();
110         if (q == null || !(q instanceof SAMLAttributeQuery))
111             throw new SAMLException(SAMLException.REQUESTER,"AASaml.receive() can only respond to a SAML Attribute Query");
112         aquery = (SAMLAttributeQuery)q;
113     }
114
115     public String getHandle(){
116         return aquery.getSubject().getName();
117     }
118
119     public String getResource(){
120         return aquery.getResource();
121     }
122
123     public String getShar(){
124         return sharName.toString();
125     }
126
127  
128     public void respond(HttpServletResponse resp, Collection attrs, SAMLException exception)
129         throws IOException {        
130         SAMLException ourSE = null;
131         SAMLResponse sResp = null;
132         
133         try {
134             if(attrs == null || attrs.size() == 0) {
135                         sResp = new SAMLResponse(sreq.getRequestId(),
136                                                  /* recipient URL*/ null,
137                                                  /* no attrs -> no assersion*/ null,
138                                                  exception);
139             } else {
140                 
141                 // Determine max lifetime, and filter via query if necessary.
142                         Date now = new Date();
143                         Date then = null;
144                 long min = 0;
145                 Iterator i = attrs.iterator();
146                 outer_loop:
147                 while (i.hasNext())
148                 {
149                     SAMLAttribute attr = (SAMLAttribute)i.next();
150                     if (min == 0 || (attr.getLifetime() > 0 && attr.getLifetime() < min))
151                         min = attr.getLifetime();
152                     Iterator filter = aquery.getDesignators();
153                     if (!filter.hasNext())
154                         continue;
155                     while (filter.hasNext())
156                     {
157                         SAMLAttribute desig = (SAMLAttribute)filter.next();
158                         if (attr.getNamespace().equals(desig.getNamespace()) && attr.getName().equals(desig.getName()))
159                             continue outer_loop;
160                     }
161                     i.remove();
162                 }
163         
164                         SAMLSubject rSubject = (SAMLSubject)aquery.getSubject().clone();
165                         SAMLCondition condition = new SAMLAudienceRestrictionCondition(Arrays.asList(policies));
166                         SAMLStatement statement = new SAMLAttributeStatement(rSubject, attrs);
167                     
168                         if(min > 0)
169                             then = new Date(now.getTime() + (min*1000));
170         
171                         SAMLAssertion sAssertion = new SAMLAssertion(
172                                 myName,
173                                                      now,
174                                                      then,
175                                                      Collections.singleton(condition),
176                                                      Collections.singleton(statement)
177                                  );
178         
179                         sResp = new SAMLResponse(sreq.getRequestId(),
180                                                  /* recipient URL*/ null,
181                                                  Collections.singleton(sAssertion),
182                                                  exception);
183             }
184         } catch (SAMLException se) {
185             ourSE = se;
186         } catch (CloneNotSupportedException ex) {
187             ourSE = new SAMLException(SAMLException.RESPONDER, ex);
188         } finally{
189             binding.respond(resp,sResp,ourSE);      
190         }
191     }
192
193     public void fail(HttpServletResponse resp, SAMLException exception)
194         throws IOException{
195         try{
196             SAMLResponse sResp = new SAMLResponse((sreq!=null) ? sreq.getRequestId() : null,
197                                                   /* recipient URL*/ null,
198                                                   /* an assersion*/ null,
199                                                   exception);
200                 if (log.isDebugEnabled()) {
201                         try {
202                                 log.debug(
203                                         "Dumping generated SAML Error Response:"
204                                         + System.getProperty("line.separator")
205                                         + new String(new BASE64Decoder().decodeBuffer(new String(sResp.toBase64(), "ASCII")), "UTF8"));
206                                 } catch (IOException e) {
207                                         log.error("Encountered an error while decoding SAMLReponse for logging purposes.");
208                                 }
209                         }
210             binding.respond(resp, sResp, null);
211             log.debug("Returning SAML Error Response.");
212         }catch(SAMLException se){
213             binding.respond(resp, null, exception);
214             log.info("AA failed to make an error message: "+se);
215         }
216     }
217 }