Skip to main content

SpDescriptor

Struct SpDescriptor 

Source
pub struct SpDescriptor { /* private fields */ }
Expand description

Typed SP peer descriptor imported from metadata.

Implementations§

Source§

impl SpDescriptor

Source

pub fn from_metadata_xml_for( expected_entity_id: EntityId, xml: &str, trust: MetadataTrustPolicy<'_>, ) -> Result<Self, SamlError>

Parse SP metadata for an expected entity ID and explicit trust policy.

§Errors

Returns SamlError when the XML is malformed, the entity ID is absent or unexpected, or the requested trust policy cannot be satisfied.

Examples found in repository?
examples/sso.rs (lines 42-46)
8fn main() -> Result<(), Box<dyn std::error::Error>> {
9    use saml_rs::{
10        AcsEndpoint, AuthnRequest, BrowserInput, CertificatePem, Credentials, EntityId, IdpConfig,
11        IdpDescriptor, IdpValidationPolicy, MetadataTrustPolicy, NameId, PrivateKeyPem,
12        RelayStateParam, ReplayPolicy, RespondSso, Saml, SamlValidationContext, SpConfig,
13        SpDescriptor, SpValidationPolicy, SsoEndpoint, SsoResponse, StartSso, Subject,
14    };
15    use std::time::SystemTime;
16
17    let privkey = include_str!("../tests/fixtures/key/sp_privkey.pem");
18    let cert = include_str!("../tests/fixtures/key/sp_signing_cert.cer");
19    let credentials = || Credentials {
20        signing_key: Some(PrivateKeyPem::new(privkey)),
21        signing_certificate: Some(CertificatePem::new(cert)),
22        ..Credentials::default()
23    };
24    let validation =
25        || SamlValidationContext::new(SystemTime::now(), ReplayPolicy::DisabledForCompatibility);
26
27    let sp = Saml::sp(
28        SpConfig::builder(EntityId::try_new("https://sp.example.com/metadata")?)
29            .acs_endpoint(AcsEndpoint::post("https://sp.example.com/acs")?)
30            .credentials(credentials())
31            .validation(SpValidationPolicy::strict())
32            .build()?,
33    )?;
34    let idp = Saml::idp(
35        IdpConfig::builder(EntityId::try_new("https://idp.example.com/metadata")?)
36            .sso_endpoint(SsoEndpoint::post("https://idp.example.com/sso")?)
37            .credentials(credentials())
38            .validation(IdpValidationPolicy::strict())
39            .build()?,
40    )?;
41
42    let sp_descriptor = SpDescriptor::from_metadata_xml_for(
43        EntityId::try_new("https://sp.example.com/metadata")?,
44        sp.metadata_xml(),
45        MetadataTrustPolicy::UnsignedForCompatibility,
46    )?;
47    let idp_descriptor = IdpDescriptor::from_metadata_xml_for(
48        EntityId::try_new("https://idp.example.com/metadata")?,
49        idp.metadata_xml(),
50        MetadataTrustPolicy::UnsignedForCompatibility,
51    )?;
52
53    let relay_state = RelayStateParam::try_from_option(Some("demo-state".to_string()))?;
54    let started = sp.start_sso(&idp_descriptor, StartSso::post().relay_state(relay_state))?;
55    println!(
56        "SP  -> AuthnRequest id = {}",
57        started.pending.request_id().as_str()
58    );
59
60    let request = idp.receive_sso(
61        &sp_descriptor,
62        BrowserInput::<AuthnRequest>::post(started.outbound.post_form()?.fields().to_vec()),
63        validation(),
64    )?;
65    println!(
66        "IdP <- request issuer  = {}",
67        request.message().issuer().as_str()
68    );
69
70    let response = idp.respond_sso(
71        &sp_descriptor,
72        &request,
73        Subject::new(NameId::new("alice@example.com", None), Vec::new()),
74        RespondSso::post(),
75    )?;
76
77    let session = sp.finish_sso(
78        &idp_descriptor,
79        &started.pending,
80        BrowserInput::<SsoResponse>::post(response.post_form()?.fields().to_vec()),
81        validation(),
82    );
83    let session = session?;
84    println!("SP  <- authenticated   = {}", session.name_id().value());
85    Ok(())
86}
More examples
Hide additional examples
examples/slo.rs (lines 43-47)
7fn main() -> Result<(), Box<dyn std::error::Error>> {
8    use saml_rs::{
9        AcsEndpoint, AuthnRequest, BrowserInput, CertificatePem, Credentials, EntityId, IdpConfig,
10        IdpDescriptor, IdpValidationPolicy, LogoutRequest, LogoutResponse, MetadataTrustPolicy,
11        NameId, PrivateKeyPem, ReplayPolicy, RespondSlo, RespondSso, Saml, SamlValidationContext,
12        SloEndpoint, SpConfig, SpDescriptor, SpValidationPolicy, SsoEndpoint, SsoResponse,
13        StartSlo, StartSso, Subject,
14    };
15    use std::time::SystemTime;
16
17    let privkey = include_str!("../tests/fixtures/key/sp_privkey.pem");
18    let cert = include_str!("../tests/fixtures/key/sp_signing_cert.cer");
19    let credentials = || Credentials {
20        signing_key: Some(PrivateKeyPem::new(privkey)),
21        signing_certificate: Some(CertificatePem::new(cert)),
22        ..Credentials::default()
23    };
24    let validation =
25        || SamlValidationContext::new(SystemTime::now(), ReplayPolicy::DisabledForCompatibility);
26
27    let sp = Saml::sp(
28        SpConfig::builder(EntityId::try_new("https://sp.example.com/metadata")?)
29            .acs_endpoint(AcsEndpoint::post("https://sp.example.com/acs")?)
30            .slo_endpoint(SloEndpoint::post("https://sp.example.com/slo")?)
31            .credentials(credentials())
32            .validation(SpValidationPolicy::strict())
33            .build()?,
34    )?;
35    let idp = Saml::idp(
36        IdpConfig::builder(EntityId::try_new("https://idp.example.com/metadata")?)
37            .sso_endpoint(SsoEndpoint::post("https://idp.example.com/sso")?)
38            .slo_endpoint(SloEndpoint::post("https://idp.example.com/slo")?)
39            .credentials(credentials())
40            .validation(IdpValidationPolicy::strict())
41            .build()?,
42    )?;
43    let sp_descriptor = SpDescriptor::from_metadata_xml_for(
44        EntityId::try_new("https://sp.example.com/metadata")?,
45        sp.metadata_xml(),
46        MetadataTrustPolicy::UnsignedForCompatibility,
47    )?;
48    let idp_descriptor = IdpDescriptor::from_metadata_xml_for(
49        EntityId::try_new("https://idp.example.com/metadata")?,
50        idp.metadata_xml(),
51        MetadataTrustPolicy::UnsignedForCompatibility,
52    )?;
53
54    let sso = sp.start_sso(&idp_descriptor, StartSso::post())?;
55    let request = idp.receive_sso(
56        &sp_descriptor,
57        BrowserInput::<AuthnRequest>::post(sso.outbound.post_form()?.fields().to_vec()),
58        validation(),
59    )?;
60    let response = idp.respond_sso(
61        &sp_descriptor,
62        &request,
63        Subject::new(NameId::new("alice@example.com", None), Vec::new()),
64        RespondSso::post(),
65    )?;
66    let session = sp.finish_sso(
67        &idp_descriptor,
68        &sso.pending,
69        BrowserInput::<SsoResponse>::post(response.post_form()?.fields().to_vec()),
70        validation(),
71    )?;
72
73    let subject = session
74        .logout_subject()
75        .ok_or("session has no logout subject")?;
76    let logout = sp.start_slo(&idp_descriptor, subject, StartSlo::post())?;
77    println!("SP  -> LogoutRequest id = {}", logout.pending.id().as_str());
78
79    let logout_request = idp.receive_slo(
80        &sp_descriptor,
81        BrowserInput::<LogoutRequest>::post(logout.outbound.post_form()?.fields().to_vec()),
82        validation(),
83    )?;
84    let logout_response = idp.respond_slo(
85        &sp_descriptor,
86        &logout_request,
87        RespondSlo::post().relay_state(logout.pending.relay_state().clone()),
88    )?;
89    let completed = sp.finish_slo(
90        &idp_descriptor,
91        &logout.pending,
92        BrowserInput::<LogoutResponse>::post(logout_response.post_form()?.fields().to_vec()),
93        validation(),
94    )?;
95    println!(
96        "SP  <- LogoutResponse status = {}",
97        completed.status().unwrap_or("missing")
98    );
99    Ok(())
100}
Source

pub fn from_metadata_xml( xml: &str, trust: MetadataTrustPolicy<'_>, ) -> Result<Self, SamlError>

Parse SP metadata when the caller accepts the metadata-declared entity ID.

Prefer Self::from_metadata_xml_for when the expected entity ID is known.

§Errors

Returns SamlError when the XML is malformed, the entity ID is absent, or the requested trust policy cannot be satisfied.

Source

pub fn entity_id(&self) -> &EntityId

Metadata entity ID.

Source

pub fn metadata_xml(&self) -> &str

Original metadata XML.

Source

pub fn metadata(&self) -> &SpMetadata

Parsed SP metadata.

Source

pub fn was_verified_with_pinned_certificates(&self) -> bool

Whether this descriptor was verified with pinned signing certificates.

Source

pub fn signed_entity_descriptor_xml(&self) -> Option<&str>

Signed metadata descriptor XML when pinned metadata verification passed.

Trait Implementations§

Source§

impl Clone for SpDescriptor

Source§

fn clone(&self) -> SpDescriptor

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SpDescriptor

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V