a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster/**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Copyright (c) 2006 Sun Microsystems Inc. All Rights Reserved
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * The contents of this file are subject to the terms
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * of the Common Development and Distribution License
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * (the License). You may not use this file except in
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * compliance with the License.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * You can obtain a copy of the License at
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * https://opensso.dev.java.net/public/CDDLv1.0.html or
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * opensso/legal/CDDLv1.0.txt
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * See the License for the specific language governing
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * permission and limitations under the License.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * When distributing Covered Code, include this CDDL
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Header Notice in each file and include the License file
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * at opensso/legal/CDDLv1.0.txt.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * If applicable, add the following below the CDDL Header,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * with the fields enclosed by brackets [] replaced by
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * your own identifying information:
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * "Portions Copyrighted [year] [name of copyright owner]"
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * $Id: AssertionImpl.java,v 1.8 2009/05/09 15:43:59 mallas Exp $
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings * Portions Copyrighted 2015 ForgeRock AS.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterpackage com.sun.identity.saml2.assertion.impl;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport org.w3c.dom.Document;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport org.w3c.dom.Element;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport org.w3c.dom.Node;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport org.w3c.dom.NodeList;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.util.Collections;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.util.Date;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.util.List;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.util.ArrayList;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.text.ParseException;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.security.Key;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.security.PrivateKey;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport java.security.cert.X509Certificate;
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbingsimport java.util.Set;
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.shared.xml.XMLUtils;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.shared.DateUtils;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.common.SAML2Constants;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.common.SAML2Exception;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.common.SAML2SDKUtils;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.Assertion;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.AssertionFactory;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.AttributeStatement;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.AuthnStatement;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.AuthzDecisionStatement;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.EncryptedAssertion;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.Subject;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.Advice;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.Conditions;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.assertion.Issuer;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.xmlenc.EncManager;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterimport com.sun.identity.saml2.xmlsig.SigManager;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster/**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * The <code>Assertion</code> element is a package of information
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * that supplies one or more <code>Statement</code> made by an issuer.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * There are three kinds of assertions: Authentication, Authorization Decision,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * and Attribute assertions.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Fosterpublic class AssertionImpl implements Assertion {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private String version;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private Date issueInstant;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private Subject subject;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private Advice advice;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private String signature;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private Conditions conditions;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private String id;
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings private List<Object> statements = new ArrayList();
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings private List<AuthnStatement> authnStatements = new ArrayList();
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings private List<AuthzDecisionStatement> authzDecisionStatements = new ArrayList();
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings private List<AttributeStatement> attributeStatements = new ArrayList();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private Issuer issuer;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private boolean isMutable = true;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private String signedXMLString = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private Boolean isSignatureValid = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_ELEMENT = "Assertion";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_VERSION_ATTR = "Version";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_ID_ATTR = "ID";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_ISSUEINSTANT_ATTR = "IssueInstant";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String XSI_TYPE_ATTR = "xsi:type";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_ISSUER = "Issuer";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_SIGNATURE = "Signature";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_SUBJECT = "Subject";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_CONDITIONS = "Conditions";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_ADVICE = "Advice";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_STATEMENT = "Statement";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_AUTHNSTATEMENT = "AuthnStatement";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_AUTHZDECISIONSTATEMENT =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AuthzDecisionStatement";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public static String ASSERTION_ATTRIBUTESTATEMENT =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AttributeStatement";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Default constructor
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public AssertionImpl() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * This constructor is used to build <code>Assertion</code> object from a
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * XML string.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param xml A <code>java.lang.String</code> representing
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * a <code>Assertion</code> object
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if it could not process the XML string
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public AssertionImpl(String xml) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Document document = XMLUtils.toDOMDocument(xml, SAML2SDKUtils.debug);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (document != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Element rootElement = document.getDocumentElement();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster processElement(rootElement);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): invalid XML input");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "errorObtainingElement"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (signature != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster signedXMLString = xml;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * This constructor is used to build <code>Assertion</code> object from a
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * block of existing XML that has already been built into a DOM.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param element A <code>org.w3c.dom.Element</code> representing
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * DOM tree for <code>Assertion</code> object
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if it could not process the Element
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public AssertionImpl(Element element) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster processElement(element);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (signature != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster signedXMLString = XMLUtils.print(element,"UTF-8");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster private void processElement(Element element) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (element == null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): invalid root element");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "invalid_element"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String elemName = element.getLocalName();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (elemName == null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): local name missing");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_local_name"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!elemName.equals(ASSERTION_ELEMENT)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): invalid local name " +
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster elemName);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "invalid_local_name"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster // starts processing attributes
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String attrValue = element.getAttribute(ASSERTION_VERSION_ATTR);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((attrValue == null) || (attrValue.length() == 0)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): version missing");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_assertion_version"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster version = attrValue;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attrValue = element.getAttribute(ASSERTION_ID_ATTR);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((attrValue == null) || (attrValue.length() == 0)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): assertion id missing");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_assertion_id"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster id = attrValue;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attrValue = element.getAttribute(ASSERTION_ISSUEINSTANT_ATTR);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((attrValue == null) || (attrValue.length() == 0)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): issue instant missing");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_issue_instant"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster try {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster issueInstant = DateUtils.stringToDate(attrValue);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } catch (ParseException pe) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): invalid issue instant");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "invalid_date_format"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster // starts processing subelements
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster NodeList nodes = element.getChildNodes();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster int numOfNodes = nodes.getLength();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (numOfNodes < 1) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): assertion has no subelements");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_subelements"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AssertionFactory factory = AssertionFactory.getInstance();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster int nextElem = 0;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Node child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster while (child.getNodeType() != Node.ELEMENT_NODE) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (++nextElem >= numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error("AssertionImpl.processElement():"
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster + " assertion has no subelements");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_subelements"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster // The first subelement should be <Issuer>
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String childName = child.getLocalName();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((childName == null) || (!childName.equals(ASSERTION_ISSUER))) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error("AssertionImpl.processElement():"+
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster " the first element is not <Issuer>");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_subelement_issuer"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster issuer = factory.getInstance().createIssuer((Element)child);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (++nextElem >= numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster while (child.getNodeType() != Node.ELEMENT_NODE) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (++nextElem >= numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster // The next subelement may be <ds:Signature>
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName = child.getLocalName();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((childName != null) &&
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName.equals(ASSERTION_SIGNATURE)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster signature = XMLUtils.print((Element)child);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (++nextElem >= numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster while (child.getNodeType() != Node.ELEMENT_NODE) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (++nextElem >= numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName = child.getLocalName();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster signature = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster // The next subelement may be <Subject>
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((childName != null) &&
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName.equals(ASSERTION_SUBJECT)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster subject = factory.createSubject((Element)child);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (++nextElem >= numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster while (child.getNodeType() != Node.ELEMENT_NODE) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (++nextElem >= numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName = child.getLocalName();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster subject = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster // The next subelement may be <Conditions>
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((childName != null) &&
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName.equals(ASSERTION_CONDITIONS)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster conditions = factory.createConditions((Element)child);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (++nextElem >= numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster while (child.getNodeType() != Node.ELEMENT_NODE) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (++nextElem >= numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName = child.getLocalName();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster conditions = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster // The next subelement may be <Advice>
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((childName != null) &&
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName.equals(ASSERTION_ADVICE)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster advice = factory.createAdvice((Element)child);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster nextElem++;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster advice = null;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster // The next subelements are all statements
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster while (nextElem < numOfNodes) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster child = (Node)nodes.item(nextElem);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (child.getNodeType() == Node.ELEMENT_NODE) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName = child.getLocalName();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (childName != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (childName.equals(ASSERTION_AUTHNSTATEMENT)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authnStatements.add(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster factory.createAuthnStatement((Element)child));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else if (childName.equals(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ASSERTION_AUTHZDECISIONSTATEMENT)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authzDecisionStatements.add(factory.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster createAuthzDecisionStatement((Element)child));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else if (childName.equals(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ASSERTION_ATTRIBUTESTATEMENT)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attributeStatements.add(factory.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster createAttributeStatement((Element)child));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else if ((childName != null) &&
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster childName.equals(ASSERTION_SIGNATURE)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster signature = XMLUtils.print((Element)child);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String type = ((Element)child).getAttribute(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster XSI_TYPE_ATTR);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (childName.equals(ASSERTION_STATEMENT) &&
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster (type != null && type.length() > 0)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster statements.add(XMLUtils.print((Element)child));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster } else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.processElement(): " +
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "unexpected subelement " + childName);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster getString("unexpected_subelement"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster nextElem++;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the version number of the assertion.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return The version number of the assertion.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public String getVersion() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return version;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the version number of the assertion.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param version the version number.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public void setVersion(String version) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster this.version = version;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the time when the assertion was issued
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the time of the assertion issued
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public Date getIssueInstant() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return issueInstant;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Set the time when the assertion was issued
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param issueInstant the issue time of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public void setIssueInstant(Date issueInstant) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster this.issueInstant = issueInstant;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the subject of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the subject of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public Subject getSubject() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return subject;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the subject of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param subject the subject of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public void setSubject(Subject subject) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster this.subject = subject;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the advice of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the advice of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public Advice getAdvice() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return advice;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the advice of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param advice the advice of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public void setAdvice(Advice advice) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster this.advice = advice;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the signature of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the signature of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public String getSignature() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return signature;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the conditions of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the conditions of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public Conditions getConditions() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return conditions;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the conditions of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param conditions the conditions of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public void setConditions(Conditions conditions) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster this.conditions = conditions;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the id of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the id of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public String getID() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return id;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the id of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param id the id of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public void setID(String id) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster this.id = id;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings public List<Object> getStatements() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return statements;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the Authn statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the Authn statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings public List<AuthnStatement> getAuthnStatements() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return authnStatements;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the <code>AuthzDecisionStatements</code> of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the <code>AuthzDecisionStatements</code> of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings public List<AuthzDecisionStatement> getAuthzDecisionStatements() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return authzDecisionStatements;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the attribute statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the attribute statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings public List<AttributeStatement> getAttributeStatements() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return attributeStatements;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param statements the statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings public void setStatements(List<Object> statements) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster this.statements = statements;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the <code>AuthnStatements</code> of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param statements the <code>AuthnStatements</code> of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings public void setAuthnStatements(List<AuthnStatement> statements) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authnStatements = statements;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the <code>AuthzDecisionStatements</code> of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param statements the <code>AuthzDecisionStatements</code> of
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings public void setAuthzDecisionStatements(List<AuthzDecisionStatement> statements)
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authzDecisionStatements = statements;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the attribute statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param statements the attribute statements of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings public void setAttributeStatements(List<AttributeStatement> statements) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attributeStatements = statements;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns the issuer of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return the issuer of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public Issuer getIssuer() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return issuer;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sets the issuer of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param issuer the issuer of the assertion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if the object is immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public void setIssuer(Issuer issuer) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (!isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "objectImmutable"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster this.issuer = issuer;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Return whether the assertion is signed
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return true if the assertion is signed; false otherwise.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public boolean isSigned() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return (signature != null);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings public boolean isSignatureValid(Set<X509Certificate> verificationCerts)
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (isSignatureValid == null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (signedXMLString == null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster signedXMLString = toXMLString(true, true);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings isSignatureValid = SigManager.getSigInstance().verify(signedXMLString, getID(), verificationCerts);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return isSignatureValid.booleanValue();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Sign the Assertion.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param privateKey Signing key
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param cert Certificate which contain the public key correlated to
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * the signing key; It if is not null, then the signature
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * will include the certificate; Otherwise, the signature
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * will not include any certificate
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if it could not sign the assertion.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public void sign(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster PrivateKey privateKey,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster X509Certificate cert
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Element signatureElement =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SigManager.getSigInstance().sign(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster toXMLString(true, true),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster getID(),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster privateKey,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster cert
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster );
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster signature = XMLUtils.print(signatureElement);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster signedXMLString = XMLUtils.print(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster signatureElement.getOwnerDocument().
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster getDocumentElement(), "UTF-8");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns an <code>EncryptedAssertion</code> object.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param recipientPublicKey Public key used to encrypt the data encryption
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * (secret) key, it is the public key of the
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * recipient of the XML document to be encrypted.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param dataEncAlgorithm Data encryption algorithm.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param dataEncStrength Data encryption strength.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param recipientEntityID Unique identifier of the recipient, it is used
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * as the index to the cached secret key so that
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * the key can be reused for the same recipient;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * It can be null in which case the secret key will
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * be generated every time and will not be cached
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * and reused. Note that the generation of a secret
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * key is a relatively expensive operation.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return <code>EncryptedAssertion</code> object
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @throws SAML2Exception if error occurs during the encryption process.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public EncryptedAssertion encrypt(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Key recipientPublicKey,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String dataEncAlgorithm,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster int dataEncStrength,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String recipientEntityID
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster ) throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster Element el = EncManager.getEncInstance().encrypt(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster toXMLString(true, true),
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster recipientPublicKey,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster dataEncAlgorithm,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster dataEncStrength,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster recipientEntityID,
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "EncryptedAssertion"
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster );
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return AssertionFactory.getInstance().
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster createEncryptedAssertion(el);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Gets the validity of the assertion evaluating its conditions if
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * specified.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return false if conditions is invalid based on it lying between
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * <code>NotBefore</code> (current time inclusive) and
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * <code>NotOnOrAfter</code> (current time exclusive) values
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * and true otherwise or if no conditions specified.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public boolean isTimeValid() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (conditions == null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return true;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster else {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return conditions.checkDateValidity(System.currentTimeMillis());
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns a String representation
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param includeNSPrefix Determines whether or not the namespace
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * qualifier is prepended to the Element when converted
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @param declareNS Determines whether or not the namespace is declared
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * within the Element.
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return A String representation
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if something is wrong during conversion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public String toXMLString(boolean includeNSPrefix, boolean declareNS)
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((signature != null) && (signedXMLString != null)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return signedXMLString;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster StringBuffer sb = new StringBuffer(2000);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String NS = "";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String appendNS = "";
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (declareNS) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster NS = SAML2Constants.ASSERTION_DECLARE_STR;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (includeNSPrefix) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster appendNS = SAML2Constants.ASSERTION_PREFIX;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append("<").append(appendNS).append(ASSERTION_ELEMENT).append(NS);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((version == null) || (version.length() == 0)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.toXMLString(): version missing");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_assertion_version"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(" ").append(ASSERTION_VERSION_ATTR).append("=\"").
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster append(version).append("\"");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if ((id == null) || (id.length() == 0)) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.toXMLString(): assertion id missing");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_assertion_id"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(" ").append(ASSERTION_ID_ATTR).append("=\"").
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster append(id).append("\"");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (issueInstant == null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.toXMLString(): issue instant missing");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_issue_instant"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String instantStr = DateUtils.toUTCDateFormat(issueInstant);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(" ").append(ASSERTION_ISSUEINSTANT_ATTR).append("=\"").
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster append(instantStr).append("\"").append(">\n");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (issuer == null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster SAML2SDKUtils.debug.error(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "AssertionImpl.toXMLString(): issuer missing");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster throw new SAML2Exception(SAML2SDKUtils.bundle.getString(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster "missing_subelement_issuer"));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(issuer.toXMLString(includeNSPrefix, false));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (signature != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(signature);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (subject != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(subject.toXMLString(includeNSPrefix, false));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (conditions != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(conditions.toXMLString(includeNSPrefix, false));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (advice != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(advice.toXMLString(includeNSPrefix, false));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster int length = 0;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (statements != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster length = statements.size();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster for (int i = 0; i < length; i++) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster String str = (String)statements.get(i);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(str);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (authnStatements != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster length = authnStatements.size();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster for (int i = 0; i < length; i++) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AuthnStatement st = (AuthnStatement)authnStatements.get(i);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(st.toXMLString(includeNSPrefix, false));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (authzDecisionStatements != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster length = authzDecisionStatements.size();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster for (int i = 0; i < length; i++) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AuthzDecisionStatement st =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster (AuthzDecisionStatement)authzDecisionStatements.get(i);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(st.toXMLString(includeNSPrefix, false));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (attributeStatements != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster length = attributeStatements.size();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster for (int i = 0; i < length; i++) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AttributeStatement st =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster (AttributeStatement)attributeStatements.get(i);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append(st.toXMLString(includeNSPrefix, false));
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster sb.append("</").append(appendNS).append(ASSERTION_ELEMENT).
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster append(">\n");
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster //return SAML2Utils.removeNewLineChars(sb.toString());
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return sb.toString();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns a String representation
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return A String representation
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @exception SAML2Exception if something is wrong during conversion
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public String toXMLString() throws SAML2Exception {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return this.toXMLString(true, false);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Makes the object immutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public void makeImmutable() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (isMutable) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (authnStatements != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster int length = authnStatements.size();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster for (int i = 0; i < length; i++) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AuthnStatement authn =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster (AuthnStatement)authnStatements.get(i);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authn.makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authnStatements = Collections.unmodifiableList(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authnStatements);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (authzDecisionStatements != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster int length = authzDecisionStatements.size();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster for (int i = 0; i < length; i++) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AuthzDecisionStatement authz =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster (AuthzDecisionStatement)authzDecisionStatements.get(i);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authz.makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authzDecisionStatements = Collections.unmodifiableList(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster authzDecisionStatements);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (attributeStatements != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster int length = attributeStatements.size();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster for (int i = 0; i < length; i++) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster AttributeStatement attr =
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster (AttributeStatement)attributeStatements.get(i);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attr.makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attributeStatements = Collections.unmodifiableList(
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster attributeStatements);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (statements != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster statements = Collections.unmodifiableList(statements);
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (conditions != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster conditions.makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (issuer != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster issuer.makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (subject != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster subject.makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster if (advice != null) {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster advice.makeImmutable();
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster isMutable = false;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster /**
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * Returns true if the object is mutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster *
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster * @return true if the object is mutable
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster */
449854c2a07b50ea64d9d6a8b03d18d4afeeee43Ken Stubbings @Override
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster public boolean isMutable() {
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster return isMutable;
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster }
a688bcbb4bcff5398fdd29b86f83450257dc0df4Allan Foster}