Skip to content

Commit

Permalink
read ResponseLocation from idP metadata
Browse files Browse the repository at this point in the history
  • Loading branch information
mwey committed Feb 7, 2019
1 parent ecc1abc commit ec05324
Show file tree
Hide file tree
Showing 3 changed files with 9 additions and 1 deletion.
1 change: 1 addition & 0 deletions lib/Saml2/IdPMetadataParser.php
Original file line number Diff line number Diff line change
Expand Up @@ -140,6 +140,7 @@ public static function parseXML($xml, $entityId = null, $desiredNameIdFormat = n
if ($sloNodes->length > 0) {
$metadataInfo['idp']['singleLogoutService'] = array(
'url' => $sloNodes->item(0)->getAttribute('Location'),
'responseUrl' => $sloNodes->item(0)->getAttribute('ResponseLocation'),
'binding' => $sloNodes->item(0)->getAttribute('Binding')
);
}
Expand Down
2 changes: 1 addition & 1 deletion tests/data/metadata/idp/metadata.xml
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@ WQO0LPxPqRiUqUzyhDhLo/xXNrHCu4VbMw==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.examle.com/saml/slo"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.examle.com/saml/slo" ResponseLocation="https://idp.examle.com/saml/slr"/>
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.examle.com/saml/sso"/>
</IDPSSODescriptor>
Expand Down
7 changes: 7 additions & 0 deletions tests/src/OneLogin/Saml2/IdPMetadataParserTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ public function testParseFileXML()
),
'singleLogoutService' => array (
'url' => 'https://example.onelogin.com/trust/saml2/http-redirect/slo/645460',
'responseUrl' => '',
'binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect'
),
'x509cert' => 'MIIEZTCCA02gAwIBAgIUPyy/A3bZAZ4m28PzEUUoT7RJhxIwDQYJKoZIhvcNAQEFBQAwcjELMAkGA1UEBhMCVVMxKzApBgNVBAoMIk9uZUxvZ2luIFRlc3QgKHNnYXJjaWEtdXMtcHJlcHJvZCkxFTATBgNVBAsMDE9uZUxvZ2luIElkUDEfMB0GA1UEAwwWT25lTG9naW4gQWNjb3VudCA4OTE0NjAeFw0xNjA4MDQyMjI5MzdaFw0yMTA4MDUyMjI5MzdaMHIxCzAJBgNVBAYTAlVTMSswKQYDVQQKDCJPbmVMb2dpbiBUZXN0IChzZ2FyY2lhLXVzLXByZXByb2QpMRUwEwYDVQQLDAxPbmVMb2dpbiBJZFAxHzAdBgNVBAMMFk9uZUxvZ2luIEFjY291bnQgODkxNDYwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDN6iqQGcLOCglNO42I2rkzE05UXSiMXT6c8ALThMMiaDw6qqzo3sd/tKK+NcNKWLIIC8TozWVyh5ykUiVZps+08xil7VsTU7E+wKu3kvmOsvw2wlRwtnoKZJwYhnr+RkBa+h1r3ZYUgXm1ZPeHMKj1g18KaWz9+MxYL6BhKqrOzfW/P2xxVRcFH7/pq+ZsDdgNzD2GD+apzY4MZyZj/N6BpBWJ0GlFsmtBegpbX3LBitJuFkk5L4/U/jjF1AJa3boBdCUVfATqO5G03H4XS1GySjBIRQXmlUF52rLjg6xCgWJ30/+t1X+IHLJeixiQ0vxyh6C4/usCEt94cgD1r8ADAgMBAAGjgfIwge8wDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUPW0DcH0G3IwynWgi74co4wZ6n7gwga8GA1UdIwSBpzCBpIAUPW0DcH0G3IwynWgi74co4wZ6n7ihdqR0MHIxCzAJBgNVBAYTAlVTMSswKQYDVQQKDCJPbmVMb2dpbiBUZXN0IChzZ2FyY2lhLXVzLXByZXByb2QpMRUwEwYDVQQLDAxPbmVMb2dpbiBJZFAxHzAdBgNVBAMMFk9uZUxvZ2luIEFjY291bnQgODkxNDaCFD8svwN22QGeJtvD8xFFKE+0SYcSMA4GA1UdDwEB/wQEAwIHgDANBgkqhkiG9w0BAQUFAAOCAQEAQhB4q9jrycwbHrDSoYR1X4LFFzvJ9Us75wQquRHXpdyS9D6HUBXMGI6ahPicXCQrfLgN8vzMIiqZqfySXXv/8/dxe/X4UsWLYKYJHDJmxXD5EmWTa65chjkeP1oJAc8f3CKCpcP2lOBTthbnk2fEVAeLHR4xNdQO0VvGXWO9BliYPpkYqUIBvlm+Fg9mF7AM/Uagq2503XXIE1Lq//HON68P10vNMwLSKOtYLsoTiCnuIKGJqG37MsZVjQ1ZPRcO+LSLkq0i91gFxrOrVCrgztX4JQi5XkvEsYZGIXXjwHqxTVyt3adZWQO0LPxPqRiUqUzyhDhLo/xXNrHCu4VbMw=='
Expand Down Expand Up @@ -70,6 +71,7 @@ public function testParseXML()
),
'singleLogoutService' => array (
'url' => 'https://idp.examle.com/saml/slo',
'responseUrl' => 'https://idp.examle.com/saml/slr',
'binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect'
),
'x509certMulti' => array (
Expand Down Expand Up @@ -180,6 +182,7 @@ public function testParseDesiredBindingAll()
),
"singleLogoutService" => array(
"url" => "http://idp.example.com/logout",
'responseUrl' => '',
"binding" => "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
)
)
Expand Down Expand Up @@ -297,6 +300,7 @@ public function testParseMultiCerts()
"idp" => array(
"singleLogoutService" => array(
"url" => "https://idp.examle.com/saml/slo",
'responseUrl' => '',
"binding" => "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
),
"x509certMulti" => array(
Expand Down Expand Up @@ -336,6 +340,7 @@ public function testParseMultiSigningCerts()
"idp" => array(
"singleLogoutService" => array(
"url" => "https://idp.examle.com/saml/slo",
'responseUrl' => '',
"binding" => "urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
),
"x509certMulti" => array(
Expand Down Expand Up @@ -424,6 +429,7 @@ public function testInjectIntoSettings()
),
'singleLogoutService' => array (
'url' => 'http://stuff.com/endpoints/endpoints/sls.php'

),
'NameIDFormat' => 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress'
),
Expand All @@ -435,6 +441,7 @@ public function testInjectIntoSettings()
),
'singleLogoutService' => array (
'url' => 'https://idp.adfs.example.com/adfs/ls/',
'responseUrl' => '',
'binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect'
),
'x509certMulti' => array (
Expand Down

0 comments on commit ec05324

Please sign in to comment.