Sha256: b7336df66895dfb1547b47e5e3c907a5b928b0a4a53fbd9643c45773c7610e5f

Contents?: true

Size: 1.98 KB

Versions: 6

Compression:

Stored size: 1.98 KB

Contents

module Saml
  module Kit
    module Trustable
      extend ActiveSupport::Concern

      included do
        validate :must_have_valid_signature, unless: :signature_manually_verified
        validate :must_be_registered
        validate :must_be_trusted
      end

      # Returns true when the document has an embedded XML Signature or has been verified externally.
      def signed?
        signature_manually_verified || signature.present?
      end

      # @!visibility private
      def signature
        xml_hash = to_h.fetch(name, {}).fetch('Signature', nil)
        xml_hash ? Signature.new(xml_hash) : nil
      end

      # Returns true when documents is signed and the signing certificate belongs to a known service entity.
      def trusted?
        return true if signature_manually_verified
        return false unless signed?
        signature.trusted?(provider)
      end

      # @!visibility private
      def provider
        configuration.registry.metadata_for(issuer)
      end

      # @!visibility private
      def signature_verified!
        @signature_manually_verified = true
      end

      private

      attr_reader :signature_manually_verified

      def must_have_valid_signature
        return if to_xml.blank?

        xml = ::Xml::Kit::Document.new(to_xml, namespaces: {
          "NameFormat": Namespaces::ATTR_SPLAT,
          "ds": ::Xml::Kit::Namespaces::XMLDSIG,
          "md": Namespaces::METADATA,
          "saml": Namespaces::ASSERTION,
          "samlp": Namespaces::PROTOCOL,
        })
        xml.valid?
        xml.errors.each do |attribute, error|
          errors[attribute] << error
        end
      end

      def must_be_registered
        return unless expected_type?
        return if provider.present?
        errors[:provider] << error_message(:unregistered)
      end

      def must_be_trusted
        return if trusted?
        return if provider.present? && !signed?
        errors[:fingerprint] << error_message(:invalid_fingerprint)
      end
    end
  end
end

Version data entries

6 entries across 6 versions & 1 rubygems

Version Path
saml-kit-1.0.6 lib/saml/kit/trustable.rb
saml-kit-1.0.5 lib/saml/kit/trustable.rb
saml-kit-1.0.4 lib/saml/kit/trustable.rb
saml-kit-1.0.3 lib/saml/kit/trustable.rb
saml-kit-1.0.2 lib/saml/kit/trustable.rb
saml-kit-1.0.1 lib/saml/kit/trustable.rb