4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster/**
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster *
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * Copyright (c) 2008 Sun Microsystems Inc. All Rights Reserved
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster *
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * The contents of this file are subject to the terms
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * of the Common Development and Distribution License
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * (the License). You may not use this file except in
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * compliance with the License.
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster *
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * You can obtain a copy of the License at
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * https://opensso.dev.java.net/public/CDDLv1.0.html or
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * opensso/legal/CDDLv1.0.txt
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * See the License for the specific language governing
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * permission and limitations under the License.
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster *
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * When distributing Covered Code, include this CDDL
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * Header Notice in each file and include the License file
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * at opensso/legal/CDDLv1.0.txt.
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * If applicable, add the following below the CDDL Header,
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * with the fields enclosed by brackets [] replaced by
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * your own identifying information:
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * "Portions Copyrighted [year] [name of copyright owner]"
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster *
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * $Id: CreateHostedIDP.java,v 1.9 2008/06/25 05:50:01 qcheng Exp $
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster *
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster */
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterpackage com.sun.identity.workflow;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport com.sun.identity.cot.COTException;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport com.sun.identity.saml2.common.SAML2Constants;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport com.sun.identity.saml2.jaxb.entityconfig.EntityConfigElement;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport com.sun.identity.saml2.jaxb.entityconfig.IDPSSOConfigElement;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport com.sun.identity.saml2.meta.SAML2MetaException;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport com.sun.identity.saml2.meta.SAML2MetaManager;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport com.sun.identity.saml2.meta.SAML2MetaUtils;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport java.io.UnsupportedEncodingException;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport java.net.URLEncoder;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport java.util.HashMap;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport java.util.List;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport java.util.Locale;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterimport java.util.Map;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster/**
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * Creates Hosted Identity Provider.
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster */
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Fosterpublic class CreateHostedIDP
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster extends Task {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster public CreateHostedIDP() {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster /**
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * Creates hosted identity provider.
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster *
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * @param locale Locale of the Request
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster * @param params Map of creation parameters.
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster */
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster public String execute(Locale locale, Map params)
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throws WorkflowException {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster validateParameters(params);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String metadataFile = getString(params, ParameterKeys.P_META_DATA);
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell boolean hasMetaData = (metadataFile != null) &&
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster (metadataFile.trim().length() > 0);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String metadata = null;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String extendedData = null;
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster if (hasMetaData) {
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell String extendedDataFile = getString(params,
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell ParameterKeys.P_EXTENDED_DATA);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster metadata = getContent(metadataFile, locale);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster extendedData = getContent(extendedDataFile, locale);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster } else {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String entityId = getString(params, ParameterKeys.P_ENTITY_ID);
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell String metaAlias = generateMetaAliasForIDP(getString(params,
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster ParameterKeys.P_REALM));
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster Map map = new HashMap();
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster map.put(MetaTemplateParameters.P_IDP, metaAlias);
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell map.put(MetaTemplateParameters.P_IDP_E_CERT,
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster getString(params, ParameterKeys.P_IDP_E_CERT));
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell map.put(MetaTemplateParameters.P_IDP_S_CERT,
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster getString(params, ParameterKeys.P_IDP_S_CERT));
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster try {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster metadata = CreateSAML2HostedProviderTemplate.
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster buildMetaDataTemplate(entityId, map, getRequestURL(params));
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster extendedData = CreateSAML2HostedProviderTemplate.
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell createExtendedDataTemplate(entityId, map,
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster getRequestURL(params));
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster } catch (SAML2MetaException e) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster return e.getMessage();
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String[] results = ImportSAML2MetaData.importData(
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster null, metadata, extendedData);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String realm = results[0];
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String entityId = results[1];
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String cot = getString(params, ParameterKeys.P_COT);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster if ((cot != null) && (cot.length() > 0)) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster try {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster AddProviderToCOT.addToCOT(realm, cot, entityId);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster } catch (COTException e) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throw new WorkflowException(e.getMessage());
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster try {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster List attrMapping = getAttributeMapping(params);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster if (!attrMapping.isEmpty()) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster SAML2MetaManager manager = new SAML2MetaManager();
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell EntityConfigElement config =
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster manager.getEntityConfig(realm, entityId);
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell IDPSSOConfigElement ssoConfig =
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster manager.getIDPSSOConfig(realm, entityId);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster Map attribConfig = SAML2MetaUtils.getAttributes(ssoConfig);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster List mappedAttributes = (List)attribConfig.get(
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster SAML2Constants.ATTRIBUTE_MAP);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster mappedAttributes.addAll(attrMapping);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster manager.setEntityConfig(realm, config);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster } catch (SAML2MetaException e) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throw new WorkflowException(e.getMessage());
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster try {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster return getMessage("idp.configured", locale) + "|||realm=" + realm +
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster "&entityId=" + URLEncoder.encode(entityId, "UTF-8");
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster } catch (UnsupportedEncodingException e) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throw new WorkflowException(e.getMessage());
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster private void validateParameters(Map params)
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throws WorkflowException {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String metadata = getString(params, ParameterKeys.P_META_DATA);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster boolean hasMetaData = (metadata != null) &&
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster (metadata.trim().length() > 0);
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell String extendedData = getString(params, ParameterKeys.P_EXTENDED_DATA);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster boolean hasExtendedData = (extendedData != null) &&
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster (extendedData.trim().length() > 0);
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster if ((hasMetaData && !hasExtendedData) ||
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster (!hasMetaData && hasExtendedData)
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster ) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throw new WorkflowException("both-meta-extended-data-required",
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster null);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster if ((params.size() == 3) &&
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster params.containsKey(ParameterKeys.P_META_DATA) &&
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell params.containsKey(ParameterKeys.P_EXTENDED_DATA) &&
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster !hasMetaData && !hasExtendedData
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster ) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throw new WorkflowException("both-meta-extended-data-required",
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster null);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String cotname = getString(params, ParameterKeys.P_COT);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster if ((cotname == null) || (cotname.trim().length() == 0)) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throw new WorkflowException("missing-cot", null);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster if (!hasMetaData && !hasExtendedData) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String realm = getString(params, ParameterKeys.P_REALM);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster if ((realm == null) || (realm.trim().length() == 0)) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throw new WorkflowException("missing-realm", null);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
3fc1b5e9b2ff286cd528a06154cc998198de1e70Craig McDonnell
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster String entityId = getString(params, ParameterKeys.P_ENTITY_ID);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster if ((entityId == null) || (entityId.trim().length() == 0)) {
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster throw new WorkflowException("missing-entity-id", null);
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster }
4a2f0f0be43dfd4c1b490cbf3cc48b6ba6084b1cAllan Foster}