Projet

Général

Profil

Télécharger (13,8 ko) Statistiques
| Branche: | Révision:

root / larpe / trunk / liberty.ptl @ 8843f79b

1
import libxml2
2
import urllib
3
import urlparse
4
import httplib
5

    
6
from quixote import get_field, get_request, get_response, get_session, get_session_manager, redirect
7
from quixote.directory import Directory
8
from quixote.http_request import parse_header
9

    
10
import lasso
11

    
12
import logger
13
import misc
14
import storage
15
from form import *
16
from template import *
17
from users import User
18

    
19

    
20
class RootDirectory(Directory):
21
    _q_exports = ["", "login", "assertionConsumer", "soapEndpoint",
22
            "singleLogout", "singleLogoutReturn",
23
            "federationTermination", "federationTerminationReturn",
24
            ('metadata.xml', 'metadata'), 'public_key']
25

    
26
    def perform_login(self, idp = None):
27
        server = misc.get_lasso_server()
28
        login = lasso.Login(server)
29
        login.initAuthnRequest(idp, lasso.HTTP_METHOD_REDIRECT)
30
        login.request.nameIdPolicy = "federated"
31
        login.request.forceAuthn = False
32
        login.request.isPassive = False
33
        login.request.consent = "urn:liberty:consent:obtained"
34
        login.buildAuthnRequestMsg()
35
        return redirect(login.msgUrl)
36

    
37
    def assertionConsumer(self):
38
        server = misc.get_lasso_server()
39
        if not server:
40
            return error_page(_('Liberty support is not yet configured'))
41
        login = lasso.Login(server)
42
        request = get_request()
43
        if request.get_method() == 'GET' or get_field('LAREQ'):
44
            if request.get_method() == 'GET':
45
                login.initRequest(request.get_query(), lasso.HTTP_METHOD_REDIRECT)
46
            else:
47
                login.initRequest(get_field('LAREQ'), lasso.HTTP_METHOD_POST)
48

    
49
            login.buildRequestMsg()
50
            try:
51
                soap_answer = soap_call(login.msgUrl, login.msgBody)
52
            except SOAPException:
53
                return error_page(_("Failure to communicate with identity provider"))
54
            try:
55
                login.processResponseMsg(soap_answer)
56
            except lasso.Error, error:
57
                if error[0] == lasso.LOGIN_ERROR_STATUS_NOT_SUCCESS:
58
                    return error_page(_('Unknown authentication failure'))
59
                if hasattr(lasso, 'LOGIN_ERROR_UNKNOWN_PRINCIPAL'):
60
                    if error[0] == lasso.LOGIN_ERROR_UNKNOWN_PRINCIPAL:
61
                        return error_page(_('Authentication failure; unknown principal'))
62
                return error_page(_("Identity Provider didn't accept artifact transaction."))
63
        else:
64
            login.processAuthnResponseMsg(get_field('LARES'))
65
        login.acceptSso()
66
        session = get_session()
67
        if login.isSessionDirty:
68
            if login.session:
69
                session.lasso_session_dump = login.session.dump()
70
            else:
71
                session.lasso_session_dump = None
72
        user = self.lookup_user(session, login)
73
        if user:
74
            session.set_user(user.id)
75
        else:
76
            session.set_user('anonymous-%s' % login.nameIdentifier.content)
77
            session.lasso_anonymous_identity_dump = login.identity.dump()
78

    
79
        response = get_response()
80
        if session.after_url:
81
            after_url = session.after_url
82
            session.after_url = None
83
            return redirect(after_url)
84
        response.set_status(303)
85
        response.headers['location'] = urlparse.urljoin(request.get_url(), str('..'))
86
        response.content_type = 'text/plain'
87
        return "Your browser should redirect you"
88

    
89
    def lookup_user(self, session, login):
90
        ni = login.nameIdentifier.content
91
        session.name_identifier = ni
92
        nis = list(User.select(lambda x: ni in x.name_identifiers))
93
        if nis:
94
            user = nis[0]
95
        else:
96
            if lasso.WSF_SUPPORT and misc.cfg.get('misc', {}).get('grab-user-with-wsf', False):
97
                disco = lasso.Discovery(login.server)
98
                disco.setSessionFromDump(session.lasso_session_dump)
99
                try:
100
                    disco.initQuery()
101
                except lasso.Error, error:
102
                    pass # XXX: there is no defined error code on lasso side
103
                    service = None
104
                else:
105
                    disco.addRequestedServiceType(lasso.PP_HREF)
106
                    disco.buildRequestMsg()
107
                    soap_answer = soap_call(disco.msgUrl, disco.msgBody)
108
                    disco.processQueryResponseMsg(soap_answer)
109

    
110
                    service = disco.getService()
111

    
112
                if not service:
113
                    return None
114

    
115
                service.initQuery('/pp:PP/pp:InformalName', 'name')
116
                service.addQueryItem('/pp:PP/pp:MsgContact', 'email')
117
                service.buildRequestMsg()
118
                try:
119
                    soap_answer = soap_call(service.msgUrl, service.msgBody)
120
                except SOAPException:
121
                    # it was advertised, it didn't work, too bad.
122
                    return None
123
                service.processQueryResponseMsg(soap_answer)
124

    
125
                email, name = None, None
126

    
127
                emailNode = service.getAnswer('/pp:PP/pp:MsgContact')
128
                if emailNode:
129
                    # horrible <MsgContact>; rebuild email
130
                    doc = libxml2.parseDoc(emailNode)
131
                    node = doc.children.children
132
                    account, provider = None, None
133
                    while node:
134
                        if node.name == 'MsgAccount':
135
                            account = node.getContent()
136
                        if node.name == 'MsgProvider':
137
                            provider = node.getContent()
138
                        node = node.next
139
                    if account and provider:
140
                        email = '%s@%s' % (account, provider)
141
                    else:
142
                        email = ''
143

    
144
                nameNode = service.getAnswer('/pp:PP/pp:InformalName')
145
                if nameNode:
146
                    doc = libxml2.parseDoc(nameNode)
147
                    name = unicode(doc.getContent(), 'utf-8').encode('iso-8859-1')
148
        
149
                if email and name:
150
                    user = User()
151
                    user.email = email
152
                    user.name = name
153
                    user.name_identifiers.append(login.nameIdentifier.content)
154
                    user.lasso_dump = login.identity.dump()
155
                    user.store()
156
                    return user
157

    
158
            return None
159

    
160
        user.lasso_dump = login.identity.dump()
161
        user.store()
162
        return user
163

    
164
    def singleLogout(self):
165
        request = get_request()
166
        logout = lasso.Logout(misc.get_lasso_server())
167
        if lasso.isLibertyQuery(request.get_query()):
168
            request = get_request()
169
            try:
170
                logout.processRequestMsg(request.get_query())
171
            except lasso.Error, error:
172
                if error[0] == lasso.DS_ERROR_INVALID_SIGNATURE:
173
                    return error_page(_('Failed to check single logout request signature.'))
174
                raise
175
            return self.slo_idp(logout, get_session())
176
        else:
177
            return self.slo_sp(logout, get_session())
178

    
179
    def singleLogoutReturn(self):
180
        logout = lasso.Logout(misc.get_lasso_server())
181
        try:
182
            logout.processResponseMsg(get_request().get_query())
183
        except lasso.Error, error:
184
            if error[0] == lasso.PROFILE_ERROR_INVALID_QUERY:
185
                raise AccessError()
186
            if error[0] == lasso.DS_ERROR_INVALID_SIGNATURE:
187
                return error_page(_('Failed to check single logout request signature.'))
188
            if hasattr(lasso, 'LOGOUT_ERROR_REQUEST_DENIED') and \
189
                    error[0] == lasso.LOGOUT_ERROR_REQUEST_DENIED:
190
                return redirect('/') # ignore silently
191
            elif error[0] == lasso.ERROR_UNDEFINED:
192
                # XXX: unknown status; ignoring for now.
193
                return redirect('/') # ignore silently
194
            raise
195
        return redirect('/')
196

    
197
    def slo_idp(self, logout, session):
198
        # Single Logout initiated by IdP
199
        if session.lasso_session_dump:
200
            logout.setSessionFromDump(session.lasso_session_dump)
201
        user = get_request().user
202
        if user and user.lasso_dump:
203
            logout.setIdentityFromDump(user.lasso_dump)
204
        if logout.nameIdentifier.content != session.name_identifier:
205
            raise "no appropriate name identifier in session (%s and %s)" % (
206
                    logout.nameIdentifier.content, session.name_identifier)
207

    
208
        try:
209
            logout.validateRequest()
210
        except lasso.Error, error:
211
            if error[0] != lasso.PROFILE_ERROR_SESSION_NOT_FOUND:
212
                raise
213
        else:
214
            del get_session_manager()[session.id]
215
            get_session_manager().expire_session() 
216

    
217
        logout.buildResponseMsg()
218
        if logout.msgBody: # soap answer
219
            return logout.msgBody
220
        else:
221
            return redirect(logout.msgUrl)
222

    
223
    def slo_sp(self, logout, session):
224
        if not session.user:
225
            get_session_manager().expire_session()
226
            return redirect('/')
227

    
228
        if session.lasso_session_dump:
229
            logout.setSessionFromDump(session.lasso_session_dump)
230
        user = get_request().user
231
        if user and user.lasso_dump:
232
            logout.setIdentityFromDump(user.lasso_dump)
233
        return self.slo_sp_redirect(logout)
234

    
235
    def slo_sp_redirect(self, logout):
236
        try:
237
            logout.initRequest(None, lasso.HTTP_METHOD_REDIRECT)
238
        except lasso.Error, error:
239
            if error[0] == lasso.PROFILE_ERROR_NAME_IDENTIFIER_NOT_FOUND:
240
                get_session_manager().expire_session() 
241
                return redirect('/')
242
            raise
243
        logout.buildRequestMsg()
244
        get_session_manager().expire_session() 
245
        return redirect(logout.msgUrl)
246

    
247
    def soapEndpoint(self):
248
        request = get_request()
249
        ctype = request.environ.get("CONTENT_TYPE")
250
        if not ctype:
251
            return
252

    
253
        ctype, ctype_params = parse_header(ctype)
254
        if ctype != 'text/xml':
255
            return
256

    
257
        response = get_response()
258
        response.set_content_type('text/xml')
259

    
260
        length = int(request.environ.get('CONTENT_LENGTH'))
261
        soap_message = request.stdin.read(length)
262

    
263
        request_type = lasso.getRequestTypeFromSoapMsg(soap_message) 
264

    
265
        if request_type == lasso.REQUEST_TYPE_LOGOUT:
266
            logout = lasso.Logout(misc.get_lasso_server())
267
            logout.processRequestMsg(soap_message)
268
            name_identifier = logout.nameIdentifier.content
269
            for session in get_session_manager().values():
270
                if name_identifier == session.name_identifier:
271
                    break
272
            else:
273
                raise "session not found"
274
            return self.slo_idp(logout, session)
275

    
276
        if request_type == lasso.REQUEST_TYPE_DEFEDERATION:
277
            defederation = lasso.Defederation(misc.get_lasso_server())
278
            defederation.processNotificationMsg(soap_message)
279
            name_identifier = defederation.nameIdentifier.content
280
            for session in get_session_manager().values():
281
                if name_identifier == session.name_identifier:
282
                    break
283
            else:
284
                # XXX: lookup user, not session!
285
                raise "session not found"
286
            return self.fedterm(defederation, session)
287

    
288
    def federationTermination(self):
289
        request = get_request()
290
        if not lasso.isLibertyQuery(request.get_query()):
291
            return redirect('.')
292
        
293
        defederation = lasso.Defederation(misc.get_lasso_server())
294
        defederation.processNotificationMsg(request.get_query())
295
        session = get_session()
296
        return self.fedterm(defederation, session)
297

    
298
    def fedterm(self, defederation, session):
299
        defederation.setSessionFromDump(session.lasso_session_dump)
300

    
301
        user = get_request().user
302
        if user and user.lasso_dump:
303
            defederation.setIdentityFromDump(user.lasso_dump)
304

    
305
        try:
306
            defederation.validateNotification()
307
        except lasso.Error, error:
308
            pass # ignore failure (?)
309
        else:
310
            if not defederation.identity:
311
                # if it was the last federation the whole identity dump collapsed
312
                user.lasso_dump = None
313
            else:
314
                user.lasso_dump = defederation.identity.dump()
315
            user.store()
316

    
317
        if defederation.isSessionDirty:
318
            if defederation.session:
319
                session.lasso_session_dump = defederation.session.dump()
320
            else:
321
                session.lasso_session_dump = None
322

    
323
        if defederation.msgUrl:
324
            return redirect(defederation.msgUrl)
325
        else:
326
            get_session_manager().commit_changes(session)
327
            response = get_response()
328
            response.set_status(204)
329
            return ''
330

    
331
    def federationTerminationReturn(self):
332
        return redirect('/')
333

    
334
    def metadata(self):
335
        response = get_response()
336
        response.set_content_type('text/xml', 'utf-8')
337
        metadata = unicode(open(misc.get_abs_path(
338
                        misc.cfg['sp']['metadata'])).read(), 'utf-8')
339
        return metadata
340

    
341
    def public_key(self):
342
        response = get_response()
343
        response.set_content_type('application/octet-stream')
344
        publickey = file(misc.get_abs_path(misc.cfg['sp']['publickey'])).read()
345
        return publickey
346

    
347

    
348

    
349
class SOAPException(Exception):
350
    pass
351

    
352

    
353
def soap_call(url, msg):
354
    if url.startswith('http://'):
355
        host, query = urllib.splithost(url[5:])
356
        conn = httplib.HTTPConnection(host)
357
    else:
358
        host, query = urllib.splithost(url[6:])
359
        conn = httplib.HTTPSConnection(host)
360
    conn.request("POST", query, msg, {'Content-Type': 'text/xml'})
361
    response = conn.getresponse()
362
    data = response.read()
363
    conn.close()
364
    if response.status not in (200, 204): # 204 ok for federation termination
365
        logger.warn('SOAP error (%s) (on %s)' % (response.status, url))
366
        raise SOAPException()
367
    return data
368

    
(9-9/20)