[java-identity-provider COMMIT] in /trunk: idp-attribute-filter-impl/src/main/java/net/shibboleth/idp/attribute/filte...
noreply at shibboleth.net
noreply at shibboleth.net
Thu Dec 31 11:41:49 EST 2015
Author: rdw
Date: Thu Dec 31 11:41:48 2015
New Revision: 8062
URL: http://svn.shibboleth.net/view/java-identity-provider?rev=8062&view=rev
Log:
IDP-887 Make subjects available to the Attribute Scripts
https://issues.shibboleth.net/jira/browse/IDP-887
Make the subjects available to the ScriptedDataConnected, ScriptedAttributeDefinition, ScriptedMatcher and ScriptedPolicyRule.
Plus tests
Added:
trunk/idp-attribute-resolver-impl/src/test/resources/data/net/shibboleth/idp/attribute/resolver/impl/ad/subjects.script
Modified:
trunk/idp-attribute-filter-impl/src/main/java/net/shibboleth/idp/attribute/filter/matcher/impl/ScriptedMatcher.java
trunk/idp-attribute-filter-impl/src/main/java/net/shibboleth/idp/attribute/filter/policyrule/impl/ScriptedPolicyRule.java
trunk/idp-attribute-filter-impl/src/test/java/net/shibboleth/idp/attribute/filter/matcher/impl/ScriptedMatcherTest.java
trunk/idp-attribute-filter-impl/src/test/java/net/shibboleth/idp/attribute/filter/policyrule/impl/ScriptedPolicyRuleTest.java
trunk/idp-attribute-resolver-impl/src/main/java/net/shibboleth/idp/attribute/resolver/ad/impl/ScriptedAttributeDefinition.java
trunk/idp-attribute-resolver-impl/src/main/java/net/shibboleth/idp/attribute/resolver/dc/impl/ScriptedDataConnector.java
trunk/idp-attribute-resolver-impl/src/test/java/net/shibboleth/idp/attribute/resolver/ad/impl/ScriptedAttributeTest.java
trunk/idp-attribute-resolver-impl/src/test/java/net/shibboleth/idp/attribute/resolver/dc/impl/ScriptedDataConnectorTest.java
trunk/idp-attribute-resolver-impl/src/test/resources/data/net/shibboleth/idp/attribute/resolver/impl/dc/scriptedConnector.js
trunk/idp-attribute-resolver-impl/src/test/resources/data/net/shibboleth/idp/attribute/resolver/impl/dc/v8/scriptedConnector.js
Modified: trunk/idp-attribute-filter-impl/src/main/java/net/shibboleth/idp/attribute/filter/matcher/impl/ScriptedMatcher.java
URL: http://svn.shibboleth.net/view/java-identity-provider/trunk/idp-attribute-filter-impl/src/main/java/net/shibboleth/idp/attribute/filter/matcher/impl/ScriptedMatcher.java?rev=8062&r1=8061&r2=8062&view=diff
==============================================================================
--- trunk/idp-attribute-filter-impl/src/main/java/net/shibboleth/idp/attribute/filter/matcher/impl/ScriptedMatcher.java (original)
+++ trunk/idp-attribute-filter-impl/src/main/java/net/shibboleth/idp/attribute/filter/matcher/impl/ScriptedMatcher.java Thu Dec 31 11:41:48 2015
@@ -19,6 +19,7 @@
import java.util.Collections;
import java.util.HashSet;
+import java.util.List;
import java.util.Set;
import javax.annotation.Nonnull;
@@ -27,11 +28,13 @@
import javax.script.ScriptContext;
import javax.script.ScriptException;
import javax.script.SimpleScriptContext;
+import javax.security.auth.Subject;
import net.shibboleth.idp.attribute.IdPAttribute;
import net.shibboleth.idp.attribute.IdPAttributeValue;
import net.shibboleth.idp.attribute.filter.Matcher;
import net.shibboleth.idp.attribute.filter.context.AttributeFilterContext;
+import net.shibboleth.idp.authn.context.SubjectContext;
import net.shibboleth.idp.profile.context.RelyingPartyContext;
import net.shibboleth.utilities.java.support.annotation.constraint.NonnullAfterInit;
import net.shibboleth.utilities.java.support.annotation.constraint.NonnullElements;
@@ -43,6 +46,7 @@
import net.shibboleth.utilities.java.support.logic.Constraint;
import net.shibboleth.utilities.java.support.scripting.EvaluableScript;
+import org.opensaml.messaging.context.navigate.ChildContextLookup;
import org.opensaml.messaging.context.navigate.ParentContextLookup;
import org.opensaml.profile.context.ProfileRequestContext;
import org.slf4j.Logger;
@@ -70,6 +74,9 @@
/** Strategy used to locate the {@link ProfileRequestContext} to use. */
@Nonnull private Function<AttributeFilterContext, ProfileRequestContext> prcLookupStrategy;
+ /** Strategy used to locate the {@link SubjectContext} to use. */
+ @Nonnull private Function<ProfileRequestContext, SubjectContext> scLookupStrategy;
+
/** Log prefix. */
private String logPrefix;
@@ -87,7 +94,8 @@
prcLookupStrategy =
Functions.compose(new ParentContextLookup<RelyingPartyContext, ProfileRequestContext>(),
new ParentContextLookup<AttributeFilterContext, RelyingPartyContext>());
- }
+ scLookupStrategy = new ChildContextLookup<ProfileRequestContext, SubjectContext>(SubjectContext.class);
+ }
/**
* Return the custom (externally provided) object.
@@ -103,7 +111,7 @@
*
* @param object the custom object
*/
- @Nullable public void setCustomObject(Object object) {
+ @Nullable public void setCustomObject(final Object object) {
customObject = object;
}
@@ -140,6 +148,21 @@
prcLookupStrategy = Constraint.isNotNull(strategy, "ProfileRequestContext lookup strategy cannot be null");
}
+
+ /**
+ * Set the strategy used to locate the {@link SubjectContext} associated with a given
[... 1053 lines stripped ...]
More information about the commits
mailing list