|
|||||||||||
| PREV CLASS NEXT CLASS | FRAMES NO FRAMES | ||||||||||
| SUMMARY: NESTED | FIELD | CONSTR | METHOD | DETAIL: FIELD | CONSTR | METHOD | ||||||||||
java.lang.Objectorg.globus.wsrf.impl.security.authorization.SAMLAuthorizationCallout
Calls out to a configured authorization service. The authorization service is configured using a property authzService in the service deployment descriptor.
| Field Summary | |
private SAMLRequestPortType |
authzPort
|
private java.security.cert.X509Certificate |
authzServiceCert
|
private static org.globus.util.I18n |
i18n
|
private static org.apache.commons.logging.Log |
logger
|
private boolean |
sigReq
|
private boolean |
simpleDecision
|
| Constructor Summary | |
SAMLAuthorizationCallout()
|
|
| Method Summary | |
void |
close()
this method is called by the PDP framework to indicate that the interceptor now should remove all state that was allocated in the initialize call |
private java.util.Vector |
getCertificates(org.globus.gsi.gssapi.GlobusGSSCredentialImpl credential)
|
org.w3c.dom.Node |
getPolicy(org.w3c.dom.Node policy)
gets the current policy of the PDP |
java.lang.String[] |
getPolicyNames()
gets the names (typically uris) of all the policies that the PDP supports |
void |
initialize(PDPConfig config,
java.lang.String name,
java.lang.String id)
Initializes the interceptor with configuration information that are valid up until the point when close is called. |
boolean |
isPermitted(javax.security.auth.Subject peerSubject,
javax.xml.rpc.handler.MessageContext context,
javax.xml.namespace.QName op)
this operation is called by the PDP Framework whenever the application needs to call secured operations. |
private boolean |
processAuthzStmt(java.lang.Object statement,
java.lang.String resource,
java.util.Vector actions,
org.opensaml.SAMLSubject samlSubject)
|
private boolean |
processSimpleAuthzStmt(java.lang.Object statement,
org.opensaml.SAMLSubject samlSubject)
|
org.w3c.dom.Node |
setPolicy(org.w3c.dom.Node policy)
sets the current policy of the PDP |
| Methods inherited from class java.lang.Object |
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait |
| Field Detail |
private static org.globus.util.I18n i18n
private static org.apache.commons.logging.Log logger
private SAMLRequestPortType authzPort
private boolean simpleDecision
private boolean sigReq
private java.security.cert.X509Certificate authzServiceCert
| Constructor Detail |
public SAMLAuthorizationCallout()
| Method Detail |
public void initialize(PDPConfig config,
java.lang.String name,
java.lang.String id)
throws InitializeException
Interceptor
initialize in interface Interceptorconfig - holding interceptor specific configuration
values, that may be obtained using the name paramtername - the name that should be used to access all the interceptor
local configurationid - the id in common for all interceptors in a chain (it is valid
up until close is called)
if close is not called the interceptor may assume that the id
still exists after a process restart
InitializeExceptionpublic java.lang.String[] getPolicyNames()
PDP
getPolicyNames in interface PDP
public org.w3c.dom.Node getPolicy(org.w3c.dom.Node policy)
throws InvalidPolicyException
PDP
getPolicy in interface PDPpolicy - may be used to query for a subset of a policy
InvalidPolicyException
public org.w3c.dom.Node setPolicy(org.w3c.dom.Node policy)
throws InvalidPolicyException
PDP
setPolicy in interface PDPpolicy - new policy
InvalidPolicyException
public void close()
throws CloseException
Interceptor
close in interface InterceptorCloseException
public boolean isPermitted(javax.security.auth.Subject peerSubject,
javax.xml.rpc.handler.MessageContext context,
javax.xml.namespace.QName op)
throws AuthorizationException
PDP
isPermitted in interface PDPpeerSubject - authenticated client subject with credentials
and attributescontext - holds properties of this XML message exchangeop - operation that the subject wants to invoke
AuthorizationException
private boolean processSimpleAuthzStmt(java.lang.Object statement,
org.opensaml.SAMLSubject samlSubject)
private boolean processAuthzStmt(java.lang.Object statement,
java.lang.String resource,
java.util.Vector actions,
org.opensaml.SAMLSubject samlSubject)
private java.util.Vector getCertificates(org.globus.gsi.gssapi.GlobusGSSCredentialImpl credential)
|
|||||||||||
| PREV CLASS NEXT CLASS | FRAMES NO FRAMES | ||||||||||
| SUMMARY: NESTED | FIELD | CONSTR | METHOD | DETAIL: FIELD | CONSTR | METHOD | ||||||||||