AA now properly responds to requests for specific attributes.
[java-idp.git] / src / edu / internet2 / middleware / shibboleth / aa / AASaml.java
1 /* 
2  * The Shibboleth License, Version 1. 
3  * Copyright (c) 2002 
4  * University Corporation for Advanced Internet Development, Inc. 
5  * All rights reserved
6  * 
7  * 
8  * Redistribution and use in source and binary forms, with or without 
9  * modification, are permitted provided that the following conditions are met:
10  * 
11  * Redistributions of source code must retain the above copyright notice, this 
12  * list of conditions and the following disclaimer.
13  * 
14  * Redistributions in binary form must reproduce the above copyright notice, 
15  * this list of conditions and the following disclaimer in the documentation 
16  * and/or other materials provided with the distribution, if any, must include 
17  * the following acknowledgment: "This product includes software developed by 
18  * the University Corporation for Advanced Internet Development 
19  * <http://www.ucaid.edu>Internet2 Project. Alternately, this acknowledegement 
20  * may appear in the software itself, if and wherever such third-party 
21  * acknowledgments normally appear.
22  * 
23  * Neither the name of Shibboleth nor the names of its contributors, nor 
24  * Internet2, nor the University Corporation for Advanced Internet Development, 
25  * Inc., nor UCAID may be used to endorse or promote products derived from this 
26  * software without specific prior written permission. For written permission, 
27  * please contact shibboleth@shibboleth.org
28  * 
29  * Products derived from this software may not be called Shibboleth, Internet2, 
30  * UCAID, or the University Corporation for Advanced Internet Development, nor 
31  * may Shibboleth appear in their name, without prior written permission of the 
32  * University Corporation for Advanced Internet Development.
33  * 
34  * 
35  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" 
36  * AND WITH ALL FAULTS. ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 
37  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A 
38  * PARTICULAR PURPOSE, AND NON-INFRINGEMENT ARE DISCLAIMED AND THE ENTIRE RISK 
39  * OF SATISFACTORY QUALITY, PERFORMANCE, ACCURACY, AND EFFORT IS WITH LICENSEE. 
40  * IN NO EVENT SHALL THE COPYRIGHT OWNER, CONTRIBUTORS OR THE UNIVERSITY 
41  * CORPORATION FOR ADVANCED INTERNET DEVELOPMENT, INC. BE LIABLE FOR ANY DIRECT, 
42  * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES 
43  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 
44  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND 
45  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 
46  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS 
47  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
48  */
49
50 package edu.internet2.middleware.shibboleth.aa;
51
52 /**
53  *  Attribute Authority & Release Policy
54  *  SAML Layer for AA
55  *
56  * @author     Parviz Dousti (dousti@cmu.edu)
57  * @created    June, 2002
58  */
59
60
61 import java.io.IOException;
62 import java.util.Arrays;
63 import java.util.Collection;
64 import java.util.Collections;
65 import java.util.Date;
66 import java.util.Iterator;
67
68 import javax.servlet.http.HttpServletRequest;
69 import javax.servlet.http.HttpServletResponse;
70
71 import org.apache.log4j.Logger;
72 import org.opensaml.SAMLAssertion;
73 import org.opensaml.SAMLAttributeQuery;
74 import org.opensaml.SAMLAttributeStatement;
75 import org.opensaml.SAMLAudienceRestrictionCondition;
76 import org.opensaml.SAMLBinding;
77 import org.opensaml.SAMLCondition;
78 import org.opensaml.SAMLException;
79 import org.opensaml.SAMLQuery;
80 import org.opensaml.SAMLRequest;
81 import org.opensaml.SAMLResponse;
82 import org.opensaml.SAMLStatement;
83 import org.opensaml.SAMLSubject;
84 import sun.misc.BASE64Decoder;
85
86 import edu.internet2.middleware.shibboleth.common.SAMLBindingFactory;
87
88
89 public class AASaml {
90
91     String[] policies;
92     String myName;
93     StringBuffer sharName;
94     SAMLRequest sreq;
95     SAMLAttributeQuery aquery;
96     SAMLBinding binding;
97     private static Logger log = Logger.getLogger(AASaml.class.getName());        
98
99     public AASaml(String myName, String[] policies) throws SAMLException {
100         binding = SAMLBindingFactory.getInstance(SAMLBinding.SAML_SOAP_HTTPS);
101         this.myName = myName;
102         this.policies = policies;
103     }
104
105     public void receive(HttpServletRequest req) throws SAMLException {
106         sharName=new StringBuffer();
107         sreq = binding.receive(req, sharName);
108         SAMLQuery q = sreq.getQuery();
109         if (q == null || !(q instanceof SAMLAttributeQuery))
110             throw new SAMLException(SAMLException.REQUESTER,"AASaml.receive() can only respond to a SAML Attribute Query");
111         aquery = (SAMLAttributeQuery)q;
112     }
113
114     public String getHandle(){
115         return aquery.getSubject().getName();
116     }
117
118     public String getResource(){
119         return aquery.getResource();
120     }
121
122     public String getShar(){
123         return sharName.toString();
124     }
125     
126     public Iterator getDesignators() {
127         return aquery.getDesignators();
128     }
129
130  
131     public void respond(HttpServletResponse resp, Collection attrs, SAMLException exception)
132         throws IOException {        
133         SAMLException ourSE = null;
134         SAMLResponse sResp = null;
135         
136         try {
137             if(attrs == null || attrs.size() == 0) {
138                         sResp = new SAMLResponse(sreq.getId(),
139                                                  /* recipient URL*/ null,
140                                                  /* no attrs -> no assersion*/ null,
141                                                  exception);
142                 
143             } else {
144                 
145                 // Determine max lifetime, and filter via query if necessary.
146                         Date now = new Date();
147                         Date then = null;
148                 long min = 0;
149         
150                         SAMLSubject rSubject = (SAMLSubject)aquery.getSubject().clone();
151                         SAMLCondition condition = new SAMLAudienceRestrictionCondition(Arrays.asList(policies));
152                         SAMLStatement statement = new SAMLAttributeStatement(rSubject, attrs);
153                     
154                         if(min > 0)
155                             then = new Date(now.getTime() + (min*1000));
156         
157                         SAMLAssertion sAssertion = new SAMLAssertion(
158                                 myName,
159                                                      now,
160                                                      then,
161                                                      Collections.singleton(condition),
162                                                      null,
163                                                      Collections.singleton(statement)
164                                  );
165         
166                         sResp = new SAMLResponse(sreq.getId(),
167                                                  /* recipient URL*/ null,
168                                                  Collections.singleton(sAssertion),
169                                                  exception);
170             }
171         } catch (SAMLException se) {
172             ourSE = se;
173         } catch (CloneNotSupportedException ex) {
174             ourSE = new SAMLException(SAMLException.RESPONDER, ex);
175         
176         } finally{
177         
178                 if (log.isDebugEnabled()) {
179                                 try {
180                                         log.debug(
181                                                 "Dumping generated SAML Response:"
182                                                 + System.getProperty("line.separator")
183                                                 + new String(new BASE64Decoder().decodeBuffer(new String(sResp.toBase64(), "ASCII")), "UTF8"));
184                                 } catch (IOException e) {
185                                         log.error("Encountered an error while decoding SAMLReponse for logging purposes.");
186                                 }
187                         }
188                         
189             binding.respond(resp,sResp,ourSE);      
190         }
191     }
192
193     public void fail(HttpServletResponse resp, SAMLException exception)
194         throws IOException{
195         try{
196             SAMLResponse sResp = new SAMLResponse((sreq!=null) ? sreq.getId() : null,
197                                                   /* recipient URL*/ null,
198                                                   /* an assersion*/ null,
199                                                   exception);
200                 if (log.isDebugEnabled()) {
201                         try {
202                                 log.debug(
203                                         "Dumping generated SAML Error Response:"
204                                         + System.getProperty("line.separator")
205                                         + new String(new BASE64Decoder().decodeBuffer(new String(sResp.toBase64(), "ASCII")), "UTF8"));
206                                 } catch (IOException e) {
207                                         log.error("Encountered an error while decoding SAMLReponse for logging purposes.");
208                                 }
209                         }
210             binding.respond(resp, sResp, null);
211             log.debug("Returning SAML Error Response.");
212         }catch(SAMLException se){
213             binding.respond(resp, null, exception);
214             log.info("AA failed to make an error message: "+se);
215         }
216     }
217 }