Code Review: Mapping Directory Groups to eduPersonEntitlement

Brian Moon bmoon at scu.edu
Mon Apr 10 20:26:38 EDT 2017


Looks like I included the wrong reference link.  Rather than the internet2
link, I used
https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverScriptAttributeDefinitionExamples#ResolverScriptAttributeDefinitionExamples-GenerateAffiliationbasedonGroups
(which would be nice to have updated to Shib 3).


Brian Moon
Senior System Administrator
Enterprise Systems
Santa Clara University
Office: 408.554.4830
bmoon at scu.edu

On Mon, Apr 10, 2017 at 5:19 PM, Brian Moon <bmoon at scu.edu> wrote:

> Hello all,
>
> I just wrote a script to map directory groups to eduPersonEntitlement
> strings.  Everything seems to be working fine with it, although I would
> appreciate a code review to make sure that I haven't done anything stupid
> with it, or to see if there are areas that could be better optimized.  To
> create this, I was relying on documentation available at
> https://wiki.shibboleth.net/confluence/display/IDP30/
> ScriptedAttributeDefinition and https://spaces.internet2.
> edu/display/Grouper/Exposing+Groups+Through+Shibboleth (which seemed to
> be outdated).  We are currently running IdP v3.3.1.
>
> Below is the entry in attribute-resolver.xml:
>     <AttributeDefinition xsi:type="ScriptedAttribute"
> id="eduPersonEntitlement">
>         <Dependency ref="MyLDAP" />
>         <AttributeEncoder xsi:type="SAML1String"
> name="urn:mace:dir:attribute-def:eduPersonEntitlement" encodeType="false"
> />
>         <AttributeEncoder xsi:type="SAML2String" name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7"
> friendlyName="eduPersonEntitlement" encodeType="false" />
>         <Script><![CDATA[
>           logger = Java.type("org.slf4j.LoggerFactory").getLogger("
> net.shibboleth.idp.attribute.resolver.eppnbuilder");
>           attributeStringType = Java.type("net.shibboleth.idp.attribute.
> StringAttributeValue");
>
>           // Load entitlementMap
>           logger.debug("Loading entitlementMap:
> %{idp.home}/conf/entitlement-map.js");
>           load("%{idp.home}/conf/entitlement-map.js");
>
>           // If the user has group membership
>           if(typeof memberOf != "undefined" && memberOf != null ){
>             // Then go through each group membership and add the
> appropriate entitlement
>             // The IdP will remove duplicate values so we don't need to
> worry about that here
>             for(i = 0; memberOf != null && i <
> memberOf.getValues().size(); ++i){
>               // Group names here contain the CN and the full path in the
> directory to the group.
>               // For simplicity, only the group name is extracted from
> this string.
>               var groupName = memberOf.getValues().get(i).
> split(",",1)[0].substring(3);
>
>               logger.debug("Looking for entitlements matching '" +
> groupName + "'");
>               var entitlements = entitlementMap[groupName];
>               if(entitlements != null && entitlements.length > 0) {
>                 for(j = 0; j < entitlements.length; ++j) {
>                   logger.debug("Adding entitlement of " + entitlements[j]);
>                   eduPersonEntitlement.addValue(new attributeStringType(
> entitlements[j]));
>                 }
>               }
>             }
>           }
>         ]]></Script>
>     </AttributeDefinition>
>
> Below is the content of the %{idp.home}/conf/entitlement-map.js file:
> /**
>  * This file containts the mappings of group memberships to
>  * eduPeronEntitlement.  Mappings should be in the following format:
>  *   "Group Name": [
>  *     "urn:mace:yourNamespace:entitlement:xxxx",
>  *     "urn:mace:yourNamespace:entitlement:yyyy"
>  *   ],
>  *
>  * This data structure was chosen to allow for fast lookups of directory
> groups
>  * to see if there are any associated entitlements.  The entitlements
> listed
>  * for each group are in the form of an array so that it will be able to
> support
>  * multiple entitlements for a single group.
>  */
> var entitlementMap = {
>
>   // Application1 Entitlement
>   "Entitlement-Application1": [
>     "https://entitlement/URL/for/Application1",
>     "urn:mace:yourNamespace:entitlement:application1"
>   ],
> };
>
> Thanks!
>
> Brian Moon
> Senior System Administrator
> Enterprise Systems
> Santa Clara University
> Office: 408.554.4830 <(408)%20554-4830>
> bmoon at scu.edu
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170410/9970e5da/attachment.html>


More information about the users mailing list