pub struct IdentityProvider {
pub setting: EntitySetting,
pub metadata: IdpMetadata,
}Expand description
Compatibility export for older crate-root imports. Use Saml for new integrations; advanced raw callers should import raw::IdentityProvider.
A SAML 2.0 Identity Provider: runtime EntitySetting plus parsed IdpMetadata.
Fields§
§setting: EntitySettingRuntime configuration (keys, algorithms, flags).
metadata: IdpMetadataParsed IdP metadata.
Implementations§
Source§impl IdentityProvider
impl IdentityProvider
Sourcepub fn from_metadata(
xml: &str,
setting: EntitySetting,
) -> Result<Self, SamlError>
pub fn from_metadata( xml: &str, setting: EntitySetting, ) -> Result<Self, SamlError>
Build from IdP metadata XML, merging metadata-declared flags into setting.
§Errors
Returns an error when xml is malformed, exceeds XML limits, or cannot
be parsed as IdP metadata. Metadata parser errors include invalid entity,
SSO endpoint, certificate, or signing flag declarations.
Sourcepub fn from_config(
config: &IdpMetadataConfig,
setting: EntitySetting,
) -> Result<Self, SamlError>
pub fn from_config( config: &IdpMetadataConfig, setting: EntitySetting, ) -> Result<Self, SamlError>
Build by generating IdP metadata from config, then importing it.
§Errors
Returns an error if config cannot produce valid IdP metadata, such as
when required IdP SSO metadata is missing, or if the generated metadata
cannot be parsed back into IdP metadata.
Examples found in repository?
8fn main() -> Result<(), Box<dyn std::error::Error>> {
9 use saml_rs::constants::signature_algorithm::RSA_SHA256;
10 use saml_rs::raw::metadata::{Endpoint, IdpMetadataConfig, SpMetadataConfig};
11 use saml_rs::raw::{
12 Binding, EntitySetting, HttpRequest, IdentityProvider, LoginResponseOptions,
13 ServiceProvider, User,
14 };
15
16 let privkey = include_str!("../tests/fixtures/key/sp_privkey.pem");
17 let cert = include_str!("../tests/fixtures/key/sp_signing_cert.cer");
18 let signing = || {
19 let mut setting = EntitySetting::default();
20 setting.private_key = Some(privkey.into());
21 setting.signing_cert = Some(cert.into());
22 setting.request_signature_algorithm = RSA_SHA256.into();
23 setting
24 };
25
26 let idp = IdentityProvider::from_config(
27 &IdpMetadataConfig {
28 entity_id: "https://idp.example.com/metadata".into(),
29 signing_certs: vec![cert.into()],
30 want_authn_requests_signed: true,
31 single_sign_on_service: vec![Endpoint::new(
32 Binding::Post,
33 "https://idp.example.com/sso",
34 )],
35 ..Default::default()
36 },
37 signing(),
38 )?;
39 let sp = ServiceProvider::from_config(
40 &SpMetadataConfig {
41 entity_id: "https://sp.example.com/metadata".into(),
42 authn_requests_signed: true,
43 want_assertions_signed: true,
44 signing_certs: vec![cert.into()],
45 assertion_consumer_service: vec![Endpoint::new(
46 Binding::Post,
47 "https://sp.example.com/acs",
48 )],
49 ..Default::default()
50 },
51 signing(),
52 )?;
53
54 let request = sp.create_login_request(&idp, Binding::Post, None)?;
55 let parsed = idp.parse_login_request(
56 &sp,
57 Binding::Post,
58 &HttpRequest::post(vec![("SAMLRequest".into(), request.context.clone())]),
59 )?;
60 let response = idp.create_login_response(
61 &sp,
62 Binding::Post,
63 &User::new("alice@example.com"),
64 &LoginResponseOptions {
65 in_response_to: parsed.extract.get_str("request.id"),
66 ..Default::default()
67 },
68 )?;
69 let result = sp.parse_login_response_with_request_id(
70 &idp,
71 Binding::Post,
72 &HttpRequest::post(vec![("SAMLResponse".into(), response.context)]),
73 &request.id,
74 )?;
75 println!(
76 "raw compatibility authenticated = {:?}",
77 result.extract.get_str("nameID")
78 );
79 Ok(())
80}Sourcepub fn metadata_xml(&self) -> &str
pub fn metadata_xml(&self) -> &str
The IdP metadata XML.
Sourcepub fn create_login_response(
&self,
sp: &ServiceProvider,
binding: Binding,
user: &User,
options: &LoginResponseOptions<'_>,
) -> Result<BindingContext, SamlError>
pub fn create_login_response( &self, sp: &ServiceProvider, binding: Binding, user: &User, options: &LoginResponseOptions<'_>, ) -> Result<BindingContext, SamlError>
Generate a login <Response> for sp over binding.
Requires the crypto-bergshamra feature: the response is always signed
(assertion- or message-level) and optionally encrypted. Attributes are
taken from user; options carries InResponseTo, RelayState, the
encrypt-then-sign toggle, and an optional customTagReplacement hook.
§Errors
Returns an error if binding is unsupported, the SP metadata has no ACS
endpoint for binding, response template rendering fails, the IdP
signing key or certificate configuration is missing or invalid, the
crypto-bergshamra feature is unavailable, XML signature construction
fails, the SP encryption certificate is missing when assertion
encryption is enabled, XML encryption fails, or detached-signature
construction for Redirect/SimpleSign fails.
Examples found in repository?
8fn main() -> Result<(), Box<dyn std::error::Error>> {
9 use saml_rs::constants::signature_algorithm::RSA_SHA256;
10 use saml_rs::raw::metadata::{Endpoint, IdpMetadataConfig, SpMetadataConfig};
11 use saml_rs::raw::{
12 Binding, EntitySetting, HttpRequest, IdentityProvider, LoginResponseOptions,
13 ServiceProvider, User,
14 };
15
16 let privkey = include_str!("../tests/fixtures/key/sp_privkey.pem");
17 let cert = include_str!("../tests/fixtures/key/sp_signing_cert.cer");
18 let signing = || {
19 let mut setting = EntitySetting::default();
20 setting.private_key = Some(privkey.into());
21 setting.signing_cert = Some(cert.into());
22 setting.request_signature_algorithm = RSA_SHA256.into();
23 setting
24 };
25
26 let idp = IdentityProvider::from_config(
27 &IdpMetadataConfig {
28 entity_id: "https://idp.example.com/metadata".into(),
29 signing_certs: vec![cert.into()],
30 want_authn_requests_signed: true,
31 single_sign_on_service: vec![Endpoint::new(
32 Binding::Post,
33 "https://idp.example.com/sso",
34 )],
35 ..Default::default()
36 },
37 signing(),
38 )?;
39 let sp = ServiceProvider::from_config(
40 &SpMetadataConfig {
41 entity_id: "https://sp.example.com/metadata".into(),
42 authn_requests_signed: true,
43 want_assertions_signed: true,
44 signing_certs: vec![cert.into()],
45 assertion_consumer_service: vec![Endpoint::new(
46 Binding::Post,
47 "https://sp.example.com/acs",
48 )],
49 ..Default::default()
50 },
51 signing(),
52 )?;
53
54 let request = sp.create_login_request(&idp, Binding::Post, None)?;
55 let parsed = idp.parse_login_request(
56 &sp,
57 Binding::Post,
58 &HttpRequest::post(vec![("SAMLRequest".into(), request.context.clone())]),
59 )?;
60 let response = idp.create_login_response(
61 &sp,
62 Binding::Post,
63 &User::new("alice@example.com"),
64 &LoginResponseOptions {
65 in_response_to: parsed.extract.get_str("request.id"),
66 ..Default::default()
67 },
68 )?;
69 let result = sp.parse_login_response_with_request_id(
70 &idp,
71 Binding::Post,
72 &HttpRequest::post(vec![("SAMLResponse".into(), response.context)]),
73 &request.id,
74 )?;
75 println!(
76 "raw compatibility authenticated = {:?}",
77 result.extract.get_str("nameID")
78 );
79 Ok(())
80}Sourcepub fn parse_login_request(
&self,
sp: &ServiceProvider,
binding: Binding,
request: &HttpRequest,
) -> Result<FlowResult, SamlError>
pub fn parse_login_request( &self, sp: &ServiceProvider, binding: Binding, request: &HttpRequest, ) -> Result<FlowResult, SamlError>
Parse and validate an SP login <AuthnRequest>.
§Errors
Returns an error if binding is unsupported, the request is missing
required binding parameters, the SAML payload cannot be base64/DEFLATE
decoded, XML parsing or extraction fails, the status is invalid for the
parser, the SP issuer does not match metadata, or AuthnRequest signature
validation fails when this IdP metadata requires signed requests.
Signature failures include missing signatures, untrusted SP signing
certificates, invalid detached signatures, and XML signature validation
errors.
Examples found in repository?
8fn main() -> Result<(), Box<dyn std::error::Error>> {
9 use saml_rs::constants::signature_algorithm::RSA_SHA256;
10 use saml_rs::raw::metadata::{Endpoint, IdpMetadataConfig, SpMetadataConfig};
11 use saml_rs::raw::{
12 Binding, EntitySetting, HttpRequest, IdentityProvider, LoginResponseOptions,
13 ServiceProvider, User,
14 };
15
16 let privkey = include_str!("../tests/fixtures/key/sp_privkey.pem");
17 let cert = include_str!("../tests/fixtures/key/sp_signing_cert.cer");
18 let signing = || {
19 let mut setting = EntitySetting::default();
20 setting.private_key = Some(privkey.into());
21 setting.signing_cert = Some(cert.into());
22 setting.request_signature_algorithm = RSA_SHA256.into();
23 setting
24 };
25
26 let idp = IdentityProvider::from_config(
27 &IdpMetadataConfig {
28 entity_id: "https://idp.example.com/metadata".into(),
29 signing_certs: vec![cert.into()],
30 want_authn_requests_signed: true,
31 single_sign_on_service: vec![Endpoint::new(
32 Binding::Post,
33 "https://idp.example.com/sso",
34 )],
35 ..Default::default()
36 },
37 signing(),
38 )?;
39 let sp = ServiceProvider::from_config(
40 &SpMetadataConfig {
41 entity_id: "https://sp.example.com/metadata".into(),
42 authn_requests_signed: true,
43 want_assertions_signed: true,
44 signing_certs: vec![cert.into()],
45 assertion_consumer_service: vec![Endpoint::new(
46 Binding::Post,
47 "https://sp.example.com/acs",
48 )],
49 ..Default::default()
50 },
51 signing(),
52 )?;
53
54 let request = sp.create_login_request(&idp, Binding::Post, None)?;
55 let parsed = idp.parse_login_request(
56 &sp,
57 Binding::Post,
58 &HttpRequest::post(vec![("SAMLRequest".into(), request.context.clone())]),
59 )?;
60 let response = idp.create_login_response(
61 &sp,
62 Binding::Post,
63 &User::new("alice@example.com"),
64 &LoginResponseOptions {
65 in_response_to: parsed.extract.get_str("request.id"),
66 ..Default::default()
67 },
68 )?;
69 let result = sp.parse_login_response_with_request_id(
70 &idp,
71 Binding::Post,
72 &HttpRequest::post(vec![("SAMLResponse".into(), response.context)]),
73 &request.id,
74 )?;
75 println!(
76 "raw compatibility authenticated = {:?}",
77 result.extract.get_str("nameID")
78 );
79 Ok(())
80}Trait Implementations§
Source§impl Clone for IdentityProvider
impl Clone for IdentityProvider
Source§fn clone(&self) -> IdentityProvider
fn clone(&self) -> IdentityProvider
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more