JBoss Identity SVN: r129 - in identity-federation/trunk/identity-opensaml: src and 70 other directories.
by jboss-identity-commits@lists.jboss.org
Author: anil.saldhana(a)jboss.com
Date: 2008-12-09 11:13:16 -0500 (Tue, 09 Dec 2008)
New Revision: 129
Modified:
identity-federation/trunk/identity-opensaml/
identity-federation/trunk/identity-opensaml/.classpath
identity-federation/trunk/identity-opensaml/pom.xml
identity-federation/trunk/identity-opensaml/src/
identity-federation/trunk/identity-opensaml/src/main/
identity-federation/trunk/identity-opensaml/src/main/java/
identity-federation/trunk/identity-opensaml/src/main/java/org/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org/xmlsoap/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org/xmlsoap/schemas/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org/xmlsoap/schemas/soap/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org/xmlsoap/schemas/soap/envelope/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/authenticatedtelephony/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/internetprotocol/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/internetprotocolpassword/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/kerberos/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/mobileonefactorcontract/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/mobileonefactorunregistered/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/mobiletwofactorcontract/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/mobiletwofactorunregistered/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/nomadtelephony/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/password/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/passwordprotectedtransport/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/personalizedtelephony/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/pgp/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/previoussession/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/secureremotepassword/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/smartcard/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/smartcardpki/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/softwarepki/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/spki/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/telephony/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/timesynctoken/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/tlsclient/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/x509/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/xmldsig/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/assertion/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/factories/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/generated/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/generated/runtime/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/metadata/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles/attribute/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles/attribute/dce/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles/sso/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles/sso/ecp/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/protocol/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/w3/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/w3/xmldsig/
identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/w3/xmlenc/
identity-federation/trunk/identity-opensaml/src/main/resources/
identity-federation/trunk/identity-opensaml/src/test/
identity-federation/trunk/identity-opensaml/src/test/java/
identity-federation/trunk/identity-opensaml/src/test/java/org/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/opensaml/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/opensaml/saml2/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml/v2/
identity-federation/trunk/identity-opensaml/src/test/resources/
identity-federation/trunk/identity-opensaml/src/test/resources/endorsed/
identity-federation/trunk/identity-opensaml/src/test/resources/saml/
identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/
identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest/
Log:
saml2
Property changes on: identity-federation/trunk/identity-opensaml
___________________________________________________________________
Name: svn:ignore
- target
+ target target-eclipse .settings eclipse-target
Modified: identity-federation/trunk/identity-opensaml/.classpath
===================================================================
--- identity-federation/trunk/identity-opensaml/.classpath 2008-12-09 16:12:35 UTC (rev 128)
+++ identity-federation/trunk/identity-opensaml/.classpath 2008-12-09 16:13:16 UTC (rev 129)
@@ -1,6 +1,8 @@
<?xml version="1.0" encoding="UTF-8"?>
<classpath>
<classpathentry kind="src" path="src/main/java"/>
+ <classpathentry kind="src" path="src/test/resources"/>
+ <classpathentry kind="src" path="src/main/resources"/>
<classpathentry kind="src" path="src/test/java"/>
<classpathentry kind="con" path="org.eclipse.jdt.launching.JRE_CONTAINER"/>
<classpathentry kind="var" path="M2_REPO/opensaml/opensaml/2.1.0/opensaml-2.1.0.jar"/>
@@ -18,5 +20,10 @@
<classpathentry kind="var" path="M2_REPO/joda-time/joda-time/1.5.2/joda-time-1.5.2.jar"/>
<classpathentry kind="var" path="M2_REPO/org/jboss/security/jboss-xacml-saml/2.0.3-SNAPSHOT/jboss-xacml-saml-2.0.3-SNAPSHOT.jar"/>
<classpathentry kind="var" path="M2_REPO/org/jboss/security/jboss-xacml/2.0.2.GA/jboss-xacml-2.0.2.GA.jar"/>
- <classpathentry kind="output" path="target/eclipse-classes"/>
+ <classpathentry kind="var" path="M2_REPO/sun-jaxb/jaxb-api/2.1.9/jaxb-api-2.1.9.jar"/>
+ <classpathentry kind="var" path="M2_REPO/sun-jaxb/jaxb-impl/2.1.9/jaxb-impl-2.1.9.jar"/>
+ <classpathentry kind="var" path="M2_REPO/sun-jaf/activation/1.1/activation-1.1.jar"/>
+ <classpathentry kind="var" path="M2_REPO/codehaus-stax/stax/1.1.1/stax-1.1.1.jar"/>
+ <classpathentry kind="var" path="M2_REPO/stax/stax-api/1.0/stax-api-1.0.jar"/>
+ <classpathentry kind="output" path="target-eclipse/eclipse-classes"/>
</classpath>
Modified: identity-federation/trunk/identity-opensaml/pom.xml
===================================================================
--- identity-federation/trunk/identity-opensaml/pom.xml 2008-12-09 16:12:35 UTC (rev 128)
+++ identity-federation/trunk/identity-opensaml/pom.xml 2008-12-09 16:13:16 UTC (rev 129)
@@ -101,6 +101,27 @@
<artifactId>jboss-xacml-saml</artifactId>
</dependency>
<dependency>
+ <groupId>sun-jaxb</groupId>
+ <artifactId>jaxb-api</artifactId>
+ </dependency>
+ <dependency>
+ <groupId>stax</groupId>
+ <artifactId>stax-api</artifactId>
+ <version>1.0</version>
+ </dependency>
+ <dependency>
+ <groupId>sun-jaf</groupId>
+ <artifactId>activation</artifactId>
+ <version>1.1</version>
+ <scope>test</scope>
+ </dependency>
+ <dependency>
+ <groupId>codehaus-stax</groupId>
+ <artifactId>stax</artifactId>
+ <version>1.1.1</version>
+ <scope>test</scope>
+ </dependency>
+ <dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
<scope>test</scope>
Property changes on: identity-federation/trunk/identity-opensaml/src
___________________________________________________________________
Name: svn:ignore
- target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main
___________________________________________________________________
Name: svn:ignore
- target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org/xmlsoap
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org/xmlsoap/schemas
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org/xmlsoap/schemas/soap
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/org/xmlsoap/schemas/soap/envelope
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/authenticatedtelephony
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/internetprotocol
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/internetprotocolpassword
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/kerberos
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/mobileonefactorcontract
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/mobileonefactorunregistered
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/mobiletwofactorcontract
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/mobiletwofactorunregistered
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/nomadtelephony
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/password
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/passwordprotectedtransport
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/personalizedtelephony
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/pgp
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/previoussession
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/secureremotepassword
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/smartcard
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/smartcardpki
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/softwarepki
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/spki
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/telephony
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/timesynctoken
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/tlsclient
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/x509
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/ac/classes/xmldsig
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/assertion
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/factories
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/generated
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/generated/runtime
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/metadata
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles/attribute
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles/attribute/dce
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles/sso
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/profiles/sso/ecp
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/saml/v2/protocol
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/w3
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/w3/xmldsig
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/java/org/jboss/identity/federation/w3/xmlenc
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/main/resources
___________________________________________________________________
Name: svn:ignore
- target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/opensaml
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/opensaml/saml2
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml/v2
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/resources
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/resources/endorsed
___________________________________________________________________
Name: svn:ignore
- target
target-eclipse .settings eclipse-target
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/resources/saml
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest
___________________________________________________________________
Name: svn:ignore
+ target target-eclipse .settings eclipse-target
17 years, 7 months
JBoss Identity SVN: r128 - in identity-federation/trunk/identity-opensaml/src/main/resources: schema and 1 other directory.
by jboss-identity-commits@lists.jboss.org
Author: anil.saldhana(a)jboss.com
Date: 2008-12-09 11:12:35 -0500 (Tue, 09 Dec 2008)
New Revision: 128
Added:
identity-federation/trunk/identity-opensaml/src/main/resources/schema/
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-assertion-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-auth-telephony-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ip-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ippword-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-kerberos-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobileonefactor-reg-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobileonefactor-unreg-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobiletwofactor-reg-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobiletwofactor-unreg-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-nomad-telephony-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-personal-telephony-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-pgp-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ppt-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-pword-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-session-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-smartcard-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-smartcardpki-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-softwarepki-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-spki-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-srp-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-sslcert-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-telephony-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-timesync-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-types-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-x509-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-xmldsig-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-dce-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-ecp-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-metadata-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-protocol-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-x500-2.0.xsd
identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-xacml-2.0.xsd
Log:
saml2 schemas
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-assertion-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-assertion-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-assertion-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,283 @@
+<?xml version="1.0" encoding="US-ASCII"?>
+<schema
+ targetNamespace="urn:oasis:names:tc:SAML:2.0:assertion"
+ xmlns="http://www.w3.org/2001/XMLSchema"
+ xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
+ xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
+ xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"
+ elementFormDefault="unqualified"
+ attributeFormDefault="unqualified"
+ blockDefault="substitution"
+ version="2.0">
+ <import namespace="http://www.w3.org/2000/09/xmldsig#"
+ schemaLocation="http://www.w3.org/TR/2002/REC-xmldsig-core-20020212/xmldsig-core-schema.xsd"/>
+ <import namespace="http://www.w3.org/2001/04/xmlenc#"
+ schemaLocation="http://www.w3.org/TR/2002/REC-xmlenc-core-20021210/xenc-schema.xsd"/>
+ <annotation>
+ <documentation>
+ Document identifier: saml-schema-assertion-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V1.0 (November, 2002):
+ Initial Standard Schema.
+ V1.1 (September, 2003):
+ Updates within the same V1.0 namespace.
+ V2.0 (March, 2005):
+ New assertion schema for SAML V2.0 namespace.
+ </documentation>
+ </annotation>
+ <attributeGroup name="IDNameQualifiers">
+ <attribute name="NameQualifier" type="string" use="optional"/>
+ <attribute name="SPNameQualifier" type="string" use="optional"/>
+ </attributeGroup>
+ <element name="BaseID" type="saml:BaseIDAbstractType"/>
+ <complexType name="BaseIDAbstractType" abstract="true">
+ <attributeGroup ref="saml:IDNameQualifiers"/>
+ </complexType>
+ <element name="NameID" type="saml:NameIDType"/>
+ <complexType name="NameIDType">
+ <simpleContent>
+ <extension base="string">
+ <attributeGroup ref="saml:IDNameQualifiers"/>
+ <attribute name="Format" type="anyURI" use="optional"/>
+ <attribute name="SPProvidedID" type="string" use="optional"/>
+ </extension>
+ </simpleContent>
+ </complexType>
+ <complexType name="EncryptedElementType">
+ <sequence>
+ <element ref="xenc:EncryptedData"/>
+ <element ref="xenc:EncryptedKey" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ </complexType>
+ <element name="EncryptedID" type="saml:EncryptedElementType"/>
+ <element name="Issuer" type="saml:NameIDType"/>
+ <element name="AssertionIDRef" type="NCName"/>
+ <element name="AssertionURIRef" type="anyURI"/>
+ <element name="Assertion" type="saml:AssertionType"/>
+ <complexType name="AssertionType">
+ <sequence>
+ <element ref="saml:Issuer"/>
+ <element ref="ds:Signature" minOccurs="0"/>
+ <element ref="saml:Subject" minOccurs="0"/>
+ <element ref="saml:Conditions" minOccurs="0"/>
+ <element ref="saml:Advice" minOccurs="0"/>
+ <choice minOccurs="0" maxOccurs="unbounded">
+ <element ref="saml:Statement"/>
+ <element ref="saml:AuthnStatement"/>
+ <element ref="saml:AuthzDecisionStatement"/>
+ <element ref="saml:AttributeStatement"/>
+ </choice>
+ </sequence>
+ <attribute name="Version" type="string" use="required"/>
+ <attribute name="ID" type="ID" use="required"/>
+ <attribute name="IssueInstant" type="dateTime" use="required"/>
+ </complexType>
+ <element name="Subject" type="saml:SubjectType"/>
+ <complexType name="SubjectType">
+ <choice>
+ <sequence>
+ <choice>
+ <element ref="saml:BaseID"/>
+ <element ref="saml:NameID"/>
+ <element ref="saml:EncryptedID"/>
+ </choice>
+ <element ref="saml:SubjectConfirmation" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <element ref="saml:SubjectConfirmation" maxOccurs="unbounded"/>
+ </choice>
+ </complexType>
+ <element name="SubjectConfirmation" type="saml:SubjectConfirmationType"/>
+ <complexType name="SubjectConfirmationType">
+ <sequence>
+ <choice minOccurs="0">
+ <element ref="saml:BaseID"/>
+ <element ref="saml:NameID"/>
+ <element ref="saml:EncryptedID"/>
+ </choice>
+ <element ref="saml:SubjectConfirmationData" minOccurs="0"/>
+ </sequence>
+ <attribute name="Method" type="anyURI" use="required"/>
+ </complexType>
+ <element name="SubjectConfirmationData" type="saml:SubjectConfirmationDataType"/>
+ <complexType name="SubjectConfirmationDataType" mixed="true">
+ <complexContent>
+ <restriction base="anyType">
+ <sequence>
+ <any namespace="##any" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="NotBefore" type="dateTime" use="optional"/>
+ <attribute name="NotOnOrAfter" type="dateTime" use="optional"/>
+ <attribute name="Recipient" type="anyURI" use="optional"/>
+ <attribute name="InResponseTo" type="NCName" use="optional"/>
+ <attribute name="Address" type="string" use="optional"/>
+ <anyAttribute namespace="##other" processContents="lax"/>
+ </restriction>
+ </complexContent>
+ </complexType>
+ <complexType name="KeyInfoConfirmationDataType" mixed="false">
+ <complexContent>
+ <restriction base="saml:SubjectConfirmationDataType">
+ <sequence>
+ <element ref="ds:KeyInfo" maxOccurs="unbounded"/>
+ </sequence>
+ </restriction>
+ </complexContent>
+ </complexType>
+ <element name="Conditions" type="saml:ConditionsType"/>
+ <complexType name="ConditionsType">
+ <choice minOccurs="0" maxOccurs="unbounded">
+ <element ref="saml:Condition"/>
+ <element ref="saml:AudienceRestriction"/>
+ <element ref="saml:OneTimeUse"/>
+ <element ref="saml:ProxyRestriction"/>
+ </choice>
+ <attribute name="NotBefore" type="dateTime" use="optional"/>
+ <attribute name="NotOnOrAfter" type="dateTime" use="optional"/>
+ </complexType>
+ <element name="Condition" type="saml:ConditionAbstractType"/>
+ <complexType name="ConditionAbstractType" abstract="true"/>
+ <element name="AudienceRestriction" type="saml:AudienceRestrictionType"/>
+ <complexType name="AudienceRestrictionType">
+ <complexContent>
+ <extension base="saml:ConditionAbstractType">
+ <sequence>
+ <element ref="saml:Audience" maxOccurs="unbounded"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="Audience" type="anyURI"/>
+ <element name="OneTimeUse" type="saml:OneTimeUseType" />
+ <complexType name="OneTimeUseType">
+ <complexContent>
+ <extension base="saml:ConditionAbstractType"/>
+ </complexContent>
+ </complexType>
+ <element name="ProxyRestriction" type="saml:ProxyRestrictionType"/>
+ <complexType name="ProxyRestrictionType">
+ <complexContent>
+ <extension base="saml:ConditionAbstractType">
+ <sequence>
+ <element ref="saml:Audience" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="Count" type="nonNegativeInteger" use="optional"/>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="Advice" type="saml:AdviceType"/>
+ <complexType name="AdviceType">
+ <choice minOccurs="0" maxOccurs="unbounded">
+ <element ref="saml:AssertionIDRef"/>
+ <element ref="saml:AssertionURIRef"/>
+ <element ref="saml:Assertion"/>
+ <element ref="saml:EncryptedAssertion"/>
+ <any namespace="##other" processContents="lax"/>
+ </choice>
+ </complexType>
+ <element name="EncryptedAssertion" type="saml:EncryptedElementType"/>
+ <element name="Statement" type="saml:StatementAbstractType"/>
+ <complexType name="StatementAbstractType" abstract="true"/>
+ <element name="AuthnStatement" type="saml:AuthnStatementType"/>
+ <complexType name="AuthnStatementType">
+ <complexContent>
+ <extension base="saml:StatementAbstractType">
+ <sequence>
+ <element ref="saml:SubjectLocality" minOccurs="0"/>
+ <element ref="saml:AuthnContext"/>
+ </sequence>
+ <attribute name="AuthnInstant" type="dateTime" use="required"/>
+ <attribute name="SessionIndex" type="string" use="optional"/>
+ <attribute name="SessionNotOnOrAfter" type="dateTime" use="optional"/>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="SubjectLocality" type="saml:SubjectLocalityType"/>
+ <complexType name="SubjectLocalityType">
+ <attribute name="Address" type="string" use="optional"/>
+ <attribute name="DNSName" type="string" use="optional"/>
+ </complexType>
+ <element name="AuthnContext" type="saml:AuthnContextType"/>
+ <complexType name="AuthnContextType">
+ <sequence>
+ <choice>
+ <sequence>
+ <element ref="saml:AuthnContextClassRef"/>
+ <choice minOccurs="0">
+ <element ref="saml:AuthnContextDecl"/>
+ <element ref="saml:AuthnContextDeclRef"/>
+ </choice>
+ </sequence>
+ <choice>
+ <element ref="saml:AuthnContextDecl"/>
+ <element ref="saml:AuthnContextDeclRef"/>
+ </choice>
+ </choice>
+ <element ref="saml:AuthenticatingAuthority" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ </complexType>
+ <element name="AuthnContextClassRef" type="anyURI"/>
+ <element name="AuthnContextDeclRef" type="anyURI"/>
+ <element name="AuthnContextDecl" type="anyType"/>
+ <element name="AuthenticatingAuthority" type="anyURI"/>
+ <element name="AuthzDecisionStatement" type="saml:AuthzDecisionStatementType"/>
+ <complexType name="AuthzDecisionStatementType">
+ <complexContent>
+ <extension base="saml:StatementAbstractType">
+ <sequence>
+ <element ref="saml:Action" maxOccurs="unbounded"/>
+ <element ref="saml:Evidence" minOccurs="0"/>
+ </sequence>
+ <attribute name="Resource" type="anyURI" use="required"/>
+ <attribute name="Decision" type="saml:DecisionType" use="required"/>
+ </extension>
+ </complexContent>
+ </complexType>
+ <simpleType name="DecisionType">
+ <restriction base="string">
+ <enumeration value="Permit"/>
+ <enumeration value="Deny"/>
+ <enumeration value="Indeterminate"/>
+ </restriction>
+ </simpleType>
+ <element name="Action" type="saml:ActionType"/>
+ <complexType name="ActionType">
+ <simpleContent>
+ <extension base="string">
+ <attribute name="Namespace" type="anyURI" use="required"/>
+ </extension>
+ </simpleContent>
+ </complexType>
+ <element name="Evidence" type="saml:EvidenceType"/>
+ <complexType name="EvidenceType">
+ <choice maxOccurs="unbounded">
+ <element ref="saml:AssertionIDRef"/>
+ <element ref="saml:AssertionURIRef"/>
+ <element ref="saml:Assertion"/>
+ <element ref="saml:EncryptedAssertion"/>
+ </choice>
+ </complexType>
+ <element name="AttributeStatement" type="saml:AttributeStatementType"/>
+ <complexType name="AttributeStatementType">
+ <complexContent>
+ <extension base="saml:StatementAbstractType">
+ <choice maxOccurs="unbounded">
+ <element ref="saml:Attribute"/>
+ <element ref="saml:EncryptedAttribute"/>
+ </choice>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="Attribute" type="saml:AttributeType"/>
+ <complexType name="AttributeType">
+ <sequence>
+ <element ref="saml:AttributeValue" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="Name" type="string" use="required"/>
+ <attribute name="NameFormat" type="anyURI" use="optional"/>
+ <attribute name="FriendlyName" type="string" use="optional"/>
+ <anyAttribute namespace="##other" processContents="lax"/>
+ </complexType>
+ <element name="AttributeValue" type="anyType" nillable="true"/>
+ <element name="EncryptedAttribute" type="saml:EncryptedElementType"/>
+</schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,23 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<xs:schema
+ targetNamespace="urn:oasis:names:tc:SAML:2.0:ac"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:annotation>
+ <xs:documentation>
+ Document identifier: saml-schema-authn-context-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New core authentication context schema for SAML V2.0.
+ This is just an include of all types from the schema
+ referred to in the include statement below.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:include schemaLocation="saml-schema-authn-context-types-2.0.xsd"/>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-auth-telephony-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-auth-telephony-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-auth-telephony-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,81 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:AuthenticatedTelephony"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:AuthenticatedTelephony"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:AuthenticatedTelephony
+ Document identifier: saml-schema-authn-context-auth-telephony-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="Password"/>
+ <xs:element ref="SubscriberLineNumber"/>
+ <xs:element ref="UserSuffix"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PSTN"/>
+ <xs:element ref="ISDN"/>
+ <xs:element ref="ADSL"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ip-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ip-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ip-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,65 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema
+ targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocol"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocol"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocol
+ Document identifier: saml-schema-authn-context-ip-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="IPAddress"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ippword-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ippword-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ippword-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,67 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocolPassword"
+ xmlns:ac="urn:oasis:names:tc:SAML:2.0:ac"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocolPassword"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:InternetProtocolPassword
+ Document identifier: saml-schema-authn-context-ippword-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="Password"/>
+ <xs:element ref="IPAddress"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-kerberos-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-kerberos-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-kerberos-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,83 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:Kerberos"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:Kerberos"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:Kerberos
+ Document identifier: saml-schema-authn-context-kerberos-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="RestrictedPassword"/>
+ </xs:sequence>
+ <xs:attribute name="preauth" type="xs:integer" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="SharedSecretChallengeResponse"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SharedSecretChallengeResponseType">
+ <xs:complexContent>
+ <xs:restriction base="SharedSecretChallengeResponseType">
+ <xs:attribute name="method" type="xs:anyURI" fixed="urn:oasis:names:tc:SAML:2.0:ac:classes:Kerberos"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobileonefactor-reg-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobileonefactor-reg-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobileonefactor-reg-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,186 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorContract"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorContract"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorContract
+ Document identifier: saml-schema-authn-context-mobileonefactor-reg-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="DigSig"/>
+ <xs:element ref="ZeroKnowledge"/>
+ <xs:element ref="SharedSecretChallengeResponse"/>
+ <xs:element ref="SharedSecretDynamicPlaintext"/>
+ <xs:element ref="AsymmetricDecryption"/>
+ <xs:element ref="AsymmetricKeyAgreement"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="SSL"/>
+ <xs:element ref="MobileNetworkNoEncryption"/>
+ <xs:element ref="MobileNetworkRadioEncryption"/>
+ <xs:element ref="MobileNetworkEndToEndEncryption"/>
+ <xs:element ref="WTLS"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="OperationalProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="OperationalProtectionType">
+ <xs:sequence>
+ <xs:element ref="SecurityAudit"/>
+ <xs:element ref="DeactivationCallCenter"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="TechnicalProtectionBaseType">
+ <xs:complexContent>
+ <xs:restriction base="TechnicalProtectionBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PrivateKeyProtection"/>
+ <xs:element ref="SecretKeyProtection"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrivateKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="PrivateKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SecretKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="SecretKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="KeyStorageType">
+ <xs:complexContent>
+ <xs:restriction base="KeyStorageType">
+ <xs:attribute name="medium" use="required">
+ <xs:simpleType>
+ <xs:restriction base="mediumType">
+ <xs:enumeration value="smartcard"/>
+ <xs:enumeration value="MobileDevice"/>
+ <xs:enumeration value="MobileAuthCard"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SecurityAuditType">
+ <xs:complexContent>
+ <xs:restriction base="SecurityAuditType">
+ <xs:sequence>
+ <xs:element ref="SwitchAudit"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="IdentificationType">
+ <xs:complexContent>
+ <xs:restriction base="IdentificationType">
+ <xs:sequence>
+ <xs:element ref="PhysicalVerification"/>
+ <xs:element ref="WrittenConsent"/>
+ <xs:element ref="GoverningAgreements"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="nym">
+ <xs:simpleType>
+ <xs:restriction base="nymType">
+ <xs:enumeration value="anonymity"/>
+ <xs:enumeration value="verinymity"/>
+ <xs:enumeration value="pseudonymity"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobileonefactor-unreg-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobileonefactor-unreg-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobileonefactor-unreg-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,183 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorUnregistered"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorUnregistered"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:MobileOneFactorUnregistered
+ Document identifier: saml-schema-authn-context-mobileonefactor-unreg-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="DigSig"/>
+ <xs:element ref="ZeroKnowledge"/>
+ <xs:element ref="SharedSecretChallengeResponse"/>
+ <xs:element ref="SharedSecretDynamicPlaintext"/>
+ <xs:element ref="AsymmetricDecryption"/>
+ <xs:element ref="AsymmetricKeyAgreement"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="SSL"/>
+ <xs:element ref="MobileNetworkNoEncryption"/>
+ <xs:element ref="MobileNetworkRadioEncryption"/>
+ <xs:element ref="MobileNetworkEndToEndEncryption"/>
+ <xs:element ref="WTLS"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="OperationalProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="OperationalProtectionType">
+ <xs:sequence>
+ <xs:element ref="SecurityAudit"/>
+ <xs:element ref="DeactivationCallCenter"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="TechnicalProtectionBaseType">
+ <xs:complexContent>
+ <xs:restriction base="TechnicalProtectionBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PrivateKeyProtection"/>
+ <xs:element ref="SecretKeyProtection"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrivateKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="PrivateKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SecretKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="SecretKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="KeyStorageType">
+ <xs:complexContent>
+ <xs:restriction base="KeyStorageType">
+ <xs:attribute name="medium" use="required">
+ <xs:simpleType>
+ <xs:restriction base="mediumType">
+ <xs:enumeration value="MobileDevice"/>
+ <xs:enumeration value="MobileAuthCard"/>
+ <xs:enumeration value="smartcard"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SecurityAuditType">
+ <xs:complexContent>
+ <xs:restriction base="SecurityAuditType">
+ <xs:sequence>
+ <xs:element ref="SwitchAudit"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="IdentificationType">
+ <xs:complexContent>
+ <xs:restriction base="IdentificationType">
+ <xs:sequence>
+ <xs:element ref="GoverningAgreements"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="nym">
+ <xs:simpleType>
+ <xs:restriction base="nymType">
+ <xs:enumeration value="anonymity"/>
+ <xs:enumeration value="pseudonymity"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobiletwofactor-reg-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobiletwofactor-reg-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobiletwofactor-reg-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,202 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorContract"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorContract"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorContract
+ Document identifier: saml-schema-authn-context-mobiletwofactor-reg-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="DigSig"/>
+ <xs:element ref="ZeroKnowledge"/>
+ <xs:element ref="SharedSecretChallengeResponse"/>
+ <xs:element ref="SharedSecretDynamicPlaintext"/>
+ <xs:element ref="AsymmetricDecryption"/>
+ <xs:element ref="AsymmetricKeyAgreement"/>
+ <xs:element ref="ComplexAuthenticator"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="ComplexAuthenticatorType">
+ <xs:complexContent>
+ <xs:restriction base="ComplexAuthenticatorType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="SharedSecretChallengeResponse"/>
+ <xs:element ref="SharedSecretDynamicPlaintext"/>
+ </xs:choice>
+ <xs:element ref="Password"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="SSL"/>
+ <xs:element ref="MobileNetworkNoEncryption"/>
+ <xs:element ref="MobileNetworkRadioEncryption"/>
+ <xs:element ref="MobileNetworkEndToEndEncryption"/>
+ <xs:element ref="WTLS"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="OperationalProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="OperationalProtectionType">
+ <xs:sequence>
+ <xs:element ref="SecurityAudit"/>
+ <xs:element ref="DeactivationCallCenter"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="TechnicalProtectionBaseType">
+ <xs:complexContent>
+ <xs:restriction base="TechnicalProtectionBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PrivateKeyProtection"/>
+ <xs:element ref="SecretKeyProtection"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrivateKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="PrivateKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyActivation"/>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SecretKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="SecretKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyActivation"/>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="KeyStorageType">
+ <xs:complexContent>
+ <xs:restriction base="KeyStorageType">
+ <xs:attribute name="medium" use="required">
+ <xs:simpleType>
+ <xs:restriction base="mediumType">
+ <xs:enumeration value="MobileDevice"/>
+ <xs:enumeration value="MobileAuthCard"/>
+ <xs:enumeration value="smartcard"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SecurityAuditType">
+ <xs:complexContent>
+ <xs:restriction base="SecurityAuditType">
+ <xs:sequence>
+ <xs:element ref="SwitchAudit"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="IdentificationType">
+ <xs:complexContent>
+ <xs:restriction base="IdentificationType">
+ <xs:sequence>
+ <xs:element ref="PhysicalVerification"/>
+ <xs:element ref="WrittenConsent"/>
+ <xs:element ref="GoverningAgreements"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="nym">
+ <xs:simpleType>
+ <xs:restriction base="nymType">
+ <xs:enumeration value="anonymity"/>
+ <xs:enumeration value="verinymity"/>
+ <xs:enumeration value="pseudonymity"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobiletwofactor-unreg-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobiletwofactor-unreg-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-mobiletwofactor-unreg-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,200 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorUnregistered"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorUnregistered"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorUnregistered
+ Document identifier: saml-schema-authn-context-mobiletwofactor-unreg-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="DigSig"/>
+ <xs:element ref="ZeroKnowledge"/>
+ <xs:element ref="SharedSecretChallengeResponse"/>
+ <xs:element ref="SharedSecretDynamicPlaintext"/>
+ <xs:element ref="AsymmetricDecryption"/>
+ <xs:element ref="AsymmetricKeyAgreement"/>
+ <xs:element ref="ComplexAuthenticator"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="ComplexAuthenticatorType">
+ <xs:complexContent>
+ <xs:restriction base="ComplexAuthenticatorType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="SharedSecretChallengeResponse"/>
+ <xs:element ref="SharedSecretDynamicPlaintext"/>
+ </xs:choice>
+ <xs:element ref="Password"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="SSL"/>
+ <xs:element ref="MobileNetworkNoEncryption"/>
+ <xs:element ref="MobileNetworkRadioEncryption"/>
+ <xs:element ref="MobileNetworkEndToEndEncryption"/>
+ <xs:element ref="WTLS"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="OperationalProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="OperationalProtectionType">
+ <xs:sequence>
+ <xs:element ref="SecurityAudit"/>
+ <xs:element ref="DeactivationCallCenter"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="TechnicalProtectionBaseType">
+ <xs:complexContent>
+ <xs:restriction base="TechnicalProtectionBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PrivateKeyProtection"/>
+ <xs:element ref="SecretKeyProtection"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrivateKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="PrivateKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyActivation"/>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SecretKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="SecretKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyActivation"/>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="KeyStorageType">
+ <xs:complexContent>
+ <xs:restriction base="KeyStorageType">
+ <xs:attribute name="medium" use="required">
+ <xs:simpleType>
+ <xs:restriction base="mediumType">
+ <xs:enumeration value="MobileDevice"/>
+ <xs:enumeration value="MobileAuthCard"/>
+ <xs:enumeration value="smartcard"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SecurityAuditType">
+ <xs:complexContent>
+ <xs:restriction base="SecurityAuditType">
+ <xs:sequence>
+ <xs:element ref="SwitchAudit"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="IdentificationType">
+ <xs:complexContent>
+ <xs:restriction base="IdentificationType">
+ <xs:sequence>
+ <xs:element ref="GoverningAgreements"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="nym">
+ <xs:simpleType>
+ <xs:restriction base="nymType">
+ <xs:enumeration value="anonymity"/>
+ <xs:enumeration value="pseudonymity"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-nomad-telephony-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-nomad-telephony-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-nomad-telephony-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,81 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:NomadTelephony"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:NomadTelephony"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:NomadTelephony
+ Document identifier: saml-schema-authn-context-nomad-telephony-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="Password"/>
+ <xs:element ref="SubscriberLineNumber"/>
+ <xs:element ref="UserSuffix"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PSTN"/>
+ <xs:element ref="ISDN"/>
+ <xs:element ref="ADSL"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-personal-telephony-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-personal-telephony-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-personal-telephony-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,80 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:PersonalizedTelephony"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:PersonalizedTelephony"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:PersonalizedTelephony
+ Document identifier: saml-schema-authn-context-personal-telephony-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="SubscriberLineNumber"/>
+ <xs:element ref="UserSuffix"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PSTN"/>
+ <xs:element ref="ISDN"/>
+ <xs:element ref="ADSL"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-pgp-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-pgp-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-pgp-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,83 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:PGP"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:PGP"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:PGP
+ Document identifier: saml-schema-authn-context-pgp-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="RestrictedPassword"/>
+ </xs:sequence>
+ <xs:attribute name="preauth" type="xs:integer" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="DigSig"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PublicKeyType">
+ <xs:complexContent>
+ <xs:restriction base="PublicKeyType">
+ <xs:attribute name="keyValidation" fixed="urn:oasis:names:tc:SAML:2.0:ac:classes:PGP"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ppt-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ppt-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-ppt-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,81 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
+ Document identifier: saml-schema-authn-context-ppt-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="RestrictedPassword"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="SSL"/>
+ <xs:element ref="MobileNetworkRadioEncryption"/>
+ <xs:element ref="MobileNetworkEndToEndEncryption"/>
+ <xs:element ref="WTLS"/>
+ <xs:element ref="IPSec"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-pword-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-pword-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-pword-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,64 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:Password"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:Password"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:Password
+ Document identifier: saml-schema-authn-context-pword-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="RestrictedPassword"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-session-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-session-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-session-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,64 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession
+ Document identifier: saml-schema-authn-context-session-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="PreviousSession"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-smartcard-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-smartcard-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-smartcard-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,64 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:Smartcard"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:Smartcard"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:Smartcard
+ Document identifier: saml-schema-authn-context-smartcard-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="Smartcard"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-smartcardpki-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-smartcardpki-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-smartcardpki-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,129 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:SmartcardPKI"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:SmartcardPKI"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:SmartcardPKI
+ Document identifier: saml-schema-authn-context-smartcardpki-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="TechnicalProtectionBaseType">
+ <xs:complexContent>
+ <xs:restriction base="TechnicalProtectionBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PrivateKeyProtection"/>
+ </xs:choice>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="Smartcard"/>
+ <xs:element ref="ActivationPin"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="DigSig"/>
+ <xs:element ref="AsymmetricDecryption"/>
+ <xs:element ref="AsymmetricKeyAgreement"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrivateKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="PrivateKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyActivation"/>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="KeyActivationType">
+ <xs:complexContent>
+ <xs:restriction base="KeyActivationType">
+ <xs:sequence>
+ <xs:element ref="ActivationPin"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="KeyStorageType">
+ <xs:complexContent>
+ <xs:restriction base="KeyStorageType">
+ <xs:attribute name="medium" use="required">
+ <xs:simpleType>
+ <xs:restriction base="mediumType">
+ <xs:enumeration value="smartcard"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-softwarepki-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-softwarepki-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-softwarepki-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,129 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:SoftwarePKI"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:SoftwarePKI"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:SoftwarePKI
+ Document identifier: saml-schema-authn-context-softwarepki-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="TechnicalProtectionBaseType">
+ <xs:complexContent>
+ <xs:restriction base="TechnicalProtectionBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PrivateKeyProtection"/>
+ </xs:choice>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="ActivationPin"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="DigSig"/>
+ <xs:element ref="AsymmetricDecryption"/>
+ <xs:element ref="AsymmetricKeyAgreement"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrivateKeyProtectionType">
+ <xs:complexContent>
+ <xs:restriction base="PrivateKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyActivation"/>
+ <xs:element ref="KeyStorage"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="KeyActivationType">
+ <xs:complexContent>
+ <xs:restriction base="KeyActivationType">
+ <xs:sequence>
+ <xs:element ref="ActivationPin"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="KeyStorageType">
+ <xs:complexContent>
+ <xs:restriction base="KeyStorageType">
+ <xs:attribute name="medium" use="required">
+ <xs:simpleType>
+ <xs:restriction base="mediumType">
+ <xs:enumeration value="memory"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-spki-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-spki-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-spki-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,83 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:SPKI"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:SPKI"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:SPKI
+ Document identifier: saml-schema-authn-context-spki-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="RestrictedPassword"/>
+ </xs:sequence>
+ <xs:attribute name="preauth" type="xs:integer" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="DigSig"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PublicKeyType">
+ <xs:complexContent>
+ <xs:restriction base="PublicKeyType">
+ <xs:attribute name="keyValidation" fixed="urn:oasis:names:tc:SAML:2.0:ac:classes:SPKI"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-srp-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-srp-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-srp-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,82 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:SecureRemotePassword"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:SecureRemotePassword"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:SecureRemotePassword
+ Document identifier: saml-schema-authn-context-srp-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="RestrictedPassword"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="SharedSecretChallengeResponse"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="SharedSecretChallengeResponseType">
+ <xs:complexContent>
+ <xs:restriction base="SharedSecretChallengeResponseType">
+ <xs:attribute name="method" type="xs:anyURI" fixed="urn:ietf:rfc:2945"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-sslcert-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-sslcert-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-sslcert-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,97 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:TLSClient"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:TLSClient"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:TLSClient
+ Document identifier: saml-schema-authn-context-sslcert-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="RestrictedPassword"/>
+ </xs:sequence>
+ <xs:attribute name="preauth" type="xs:integer" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="DigSig"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PublicKeyType">
+ <xs:complexContent>
+ <xs:restriction base="PublicKeyType">
+ <xs:attribute name="keyValidation" type="xs:anyURI" fixed="urn:oasis:names:tc:SAML:2.0:ac:classes:X509"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="SSL"/>
+ <xs:element ref="WTLS"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-telephony-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-telephony-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-telephony-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,79 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:Telephony"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:Telephony"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:Telephony
+ Document identifier: saml-schema-authn-context-telephony-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="SubscriberLineNumber"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice>
+ <xs:element ref="PSTN"/>
+ <xs:element ref="ISDN"/>
+ <xs:element ref="ADSL"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
\ No newline at end of file
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-timesync-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-timesync-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-timesync-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,105 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:TimeSyncToken"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:TimeSyncToken"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:TimeSyncToken
+ Document identifier: saml-schema-authn-context-timesync-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="Token"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="TokenType">
+ <xs:complexContent>
+ <xs:restriction base="TokenType">
+ <xs:sequence>
+ <xs:element ref="TimeSyncToken"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="TimeSyncTokenType">
+ <xs:complexContent>
+ <xs:restriction base="TimeSyncTokenType">
+ <xs:attribute name="DeviceType" use="required">
+ <xs:simpleType>
+ <xs:restriction base="DeviceTypeType">
+ <xs:enumeration value="hardware"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+
+ <xs:attribute name="SeedLength" use="required">
+ <xs:simpleType>
+ <xs:restriction base="xs:integer">
+ <xs:minInclusive value="64"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+
+ <xs:attribute name="DeviceInHand" use="required">
+ <xs:simpleType>
+ <xs:restriction base="booleanType">
+ <xs:enumeration value="true"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-types-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-types-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-types-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,821 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<xs:schema
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ elementFormDefault="qualified"
+ version="2.0">
+
+ <xs:annotation>
+ <xs:documentation>
+ Document identifier: saml-schema-authn-context-types-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New core authentication context schema types for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:element name="AuthenticationContextDeclaration" type="AuthnContextDeclarationBaseType">
+ <xs:annotation>
+ <xs:documentation>
+ A particular assertion on an identity
+ provider's part with respect to the authentication
+ context associated with an authentication assertion.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="Identification" type="IdentificationType">
+ <xs:annotation>
+ <xs:documentation>
+ Refers to those characteristics that describe the
+ processes and mechanisms
+ the Authentication Authority uses to initially create
+ an association between a Principal
+ and the identity (or name) by which the Principal will
+ be known
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="PhysicalVerification">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that identification has been
+ performed in a physical
+ face-to-face meeting with the principal and not in an
+ online manner.
+ </xs:documentation>
+ </xs:annotation>
+ <xs:complexType>
+ <xs:attribute name="credentialLevel">
+ <xs:simpleType>
+ <xs:restriction base="xs:NMTOKEN">
+ <xs:enumeration value="primary"/>
+ <xs:enumeration value="secondary"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:complexType>
+ </xs:element>
+
+ <xs:element name="WrittenConsent" type="ExtensionOnlyType"/>
+
+ <xs:element name="TechnicalProtection" type="TechnicalProtectionBaseType">
+ <xs:annotation>
+ <xs:documentation>
+ Refers to those characterstics that describe how the
+ 'secret' (the knowledge or possession
+ of which allows the Principal to authenticate to the
+ Authentication Authority) is kept secure
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="SecretKeyProtection" type="SecretKeyProtectionType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates the types and strengths of
+ facilities
+ of a UA used to protect a shared secret key from
+ unauthorized access and/or use.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="PrivateKeyProtection" type="PrivateKeyProtectionType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates the types and strengths of
+ facilities
+ of a UA used to protect a private key from
+ unauthorized access and/or use.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="KeyActivation" type="KeyActivationType">
+ <xs:annotation>
+ <xs:documentation>The actions that must be performed
+ before the private key can be used. </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="KeySharing" type="KeySharingType">
+ <xs:annotation>
+ <xs:documentation>Whether or not the private key is shared
+ with the certificate authority.</xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="KeyStorage" type="KeyStorageType">
+ <xs:annotation>
+ <xs:documentation>
+ In which medium is the key stored.
+ memory - the key is stored in memory.
+ smartcard - the key is stored in a smartcard.
+ token - the key is stored in a hardware token.
+ MobileDevice - the key is stored in a mobile device.
+ MobileAuthCard - the key is stored in a mobile
+ authentication card.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="SubscriberLineNumber" type="ExtensionOnlyType"/>
+ <xs:element name="UserSuffix" type="ExtensionOnlyType"/>
+
+ <xs:element name="Password" type="PasswordType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that a password (or passphrase)
+ has been used to
+ authenticate the Principal to a remote system.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="ActivationPin" type="ActivationPinType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that a Pin (Personal
+ Identification Number) has been used to authenticate the Principal to
+ some local system in order to activate a key.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="Token" type="TokenType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that a hardware or software
+ token is used
+ as a method of identifying the Principal.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="TimeSyncToken" type="TimeSyncTokenType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that a time synchronization
+ token is used to identify the Principal. hardware -
+ the time synchonization
+ token has been implemented in hardware. software - the
+ time synchronization
+ token has been implemented in software. SeedLength -
+ the length, in bits, of the
+ random seed used in the time synchronization token.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="Smartcard" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that a smartcard is used to
+ identity the Principal.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="Length" type="LengthType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates the minimum and/or maximum
+ ASCII length of the password which is enforced (by the UA or the
+ IdP). In other words, this is the minimum and/or maximum number of
+ ASCII characters required to represent a valid password.
+ min - the minimum number of ASCII characters required
+ in a valid password, as enforced by the UA or the IdP.
+ max - the maximum number of ASCII characters required
+ in a valid password, as enforced by the UA or the IdP.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="ActivationLimit" type="ActivationLimitType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates the length of time for which an
+ PIN-based authentication is valid.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="Generation">
+ <xs:annotation>
+ <xs:documentation>
+ Indicates whether the password was chosen by the
+ Principal or auto-supplied by the Authentication Authority.
+ principalchosen - the Principal is allowed to choose
+ the value of the password. This is true even if
+ the initial password is chosen at random by the UA or
+ the IdP and the Principal is then free to change
+ the password.
+ automatic - the password is chosen by the UA or the
+ IdP to be cryptographically strong in some sense,
+ or to satisfy certain password rules, and that the
+ Principal is not free to change it or to choose a new password.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType>
+ <xs:attribute name="mechanism" use="required">
+ <xs:simpleType>
+ <xs:restriction base="xs:NMTOKEN">
+ <xs:enumeration value="principalchosen"/>
+ <xs:enumeration value="automatic"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ </xs:complexType>
+ </xs:element>
+
+ <xs:element name="AuthnMethod" type="AuthnMethodBaseType">
+ <xs:annotation>
+ <xs:documentation>
+ Refers to those characteristics that define the
+ mechanisms by which the Principal authenticates to the Authentication
+ Authority.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="PrincipalAuthenticationMechanism" type="PrincipalAuthenticationMechanismType">
+ <xs:annotation>
+ <xs:documentation>
+ The method that a Principal employs to perform
+ authentication to local system components.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="Authenticator" type="AuthenticatorBaseType">
+ <xs:annotation>
+ <xs:documentation>
+ The method applied to validate a principal's
+ authentication across a network
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="ComplexAuthenticator" type="ComplexAuthenticatorType">
+ <xs:annotation>
+ <xs:documentation>
+ Supports Authenticators with nested combinations of
+ additional complexity.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="PreviousSession" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ Indicates that the Principal has been strongly
+ authenticated in a previous session during which the IdP has set a
+ cookie in the UA. During the present session the Principal has only
+ been authenticated by the UA returning the cookie to the IdP.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="ResumeSession" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ Rather like PreviousSession but using stronger
+ security. A secret that was established in a previous session with
+ the Authentication Authority has been cached by the local system and
+ is now re-used (e.g. a Master Secret is used to derive new session
+ keys in TLS, SSL, WTLS).
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="ZeroKnowledge" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Principal has been
+ authenticated by a zero knowledge technique as specified in ISO/IEC
+ 9798-5.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="SharedSecretChallengeResponse" type="SharedSecretChallengeResponseType"/>
+
+ <xs:complexType name="SharedSecretChallengeResponseType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Principal has been
+ authenticated by a challenge-response protocol utilizing shared secret
+ keys and symmetric cryptography.
+ </xs:documentation>
+ </xs:annotation>
+ <xs:sequence>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="method" type="xs:anyURI" use="optional"/>
+ </xs:complexType>
+
+ <xs:element name="DigSig" type="PublicKeyType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Principal has been
+ authenticated by a mechanism which involves the Principal computing a
+ digital signature over at least challenge data provided by the IdP.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="AsymmetricDecryption" type="PublicKeyType">
+ <xs:annotation>
+ <xs:documentation>
+ The local system has a private key but it is used
+ in decryption mode, rather than signature mode. For example, the
+ Authentication Authority generates a secret and encrypts it using the
+ local system's public key: the local system then proves it has
+ decrypted the secret.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="AsymmetricKeyAgreement" type="PublicKeyType">
+ <xs:annotation>
+ <xs:documentation>
+ The local system has a private key and uses it for
+ shared secret key agreement with the Authentication Authority (e.g.
+ via Diffie Helman).
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:complexType name="PublicKeyType">
+ <xs:sequence>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="keyValidation" use="optional"/>
+ </xs:complexType>
+
+ <xs:element name="IPAddress" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Principal has been
+ authenticated through connection from a particular IP address.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="SharedSecretDynamicPlaintext" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ The local system and Authentication Authority
+ share a secret key. The local system uses this to encrypt a
+ randomised string to pass to the Authentication Authority.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="AuthenticatorTransportProtocol" type="AuthenticatorTransportProtocolType">
+ <xs:annotation>
+ <xs:documentation>
+ The protocol across which Authenticator information is
+ transferred to an Authentication Authority verifier.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="HTTP" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Authenticator has been
+ transmitted using bare HTTP utilizing no additional security
+ protocols.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="IPSec" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Authenticator has been
+ transmitted using a transport mechanism protected by an IPSEC session.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="WTLS" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Authenticator has been
+ transmitted using a transport mechanism protected by a WTLS session.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="MobileNetworkNoEncryption" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Authenticator has been
+ transmitted solely across a mobile network using no additional
+ security mechanism.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="MobileNetworkRadioEncryption" type="ExtensionOnlyType"/>
+ <xs:element name="MobileNetworkEndToEndEncryption" type="ExtensionOnlyType"/>
+
+ <xs:element name="SSL" type="ExtensionOnlyType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Authenticator has been
+ transmitted using a transport mechnanism protected by an SSL or TLS
+ session.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="PSTN" type="ExtensionOnlyType"/>
+ <xs:element name="ISDN" type="ExtensionOnlyType"/>
+ <xs:element name="ADSL" type="ExtensionOnlyType"/>
+
+ <xs:element name="OperationalProtection" type="OperationalProtectionType">
+ <xs:annotation>
+ <xs:documentation>
+ Refers to those characteristics that describe
+ procedural security controls employed by the Authentication Authority.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="SecurityAudit" type="SecurityAuditType"/>
+ <xs:element name="SwitchAudit" type="ExtensionOnlyType"/>
+ <xs:element name="DeactivationCallCenter" type="ExtensionOnlyType"/>
+
+ <xs:element name="GoverningAgreements" type="GoverningAgreementsType">
+ <xs:annotation>
+ <xs:documentation>
+ Provides a mechanism for linking to external (likely
+ human readable) documents in which additional business agreements,
+ (e.g. liability constraints, obligations, etc) can be placed.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="GoverningAgreementRef" type="GoverningAgreementRefType"/>
+
+ <xs:simpleType name="nymType">
+ <xs:restriction base="xs:NMTOKEN">
+ <xs:enumeration value="anonymity"/>
+ <xs:enumeration value="verinymity"/>
+ <xs:enumeration value="pseudonymity"/>
+ </xs:restriction>
+ </xs:simpleType>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod" minOccurs="0"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:complexType>
+
+ <xs:complexType name="IdentificationType">
+ <xs:sequence>
+ <xs:element ref="PhysicalVerification" minOccurs="0"/>
+ <xs:element ref="WrittenConsent" minOccurs="0"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="nym" type="nymType">
+ <xs:annotation>
+ <xs:documentation>
+ This attribute indicates whether or not the
+ Identification mechanisms allow the actions of the Principal to be
+ linked to an actual end user.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:attribute>
+ </xs:complexType>
+
+ <xs:complexType name="TechnicalProtectionBaseType">
+ <xs:sequence>
+ <xs:choice minOccurs="0">
+ <xs:element ref="PrivateKeyProtection"/>
+ <xs:element ref="SecretKeyProtection"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="OperationalProtectionType">
+ <xs:sequence>
+ <xs:element ref="SecurityAudit" minOccurs="0"/>
+ <xs:element ref="DeactivationCallCenter" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism" minOccurs="0"/>
+ <xs:element ref="Authenticator" minOccurs="0"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="GoverningAgreementsType">
+ <xs:sequence>
+ <xs:element ref="GoverningAgreementRef" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="GoverningAgreementRefType">
+ <xs:attribute name="governingAgreementRef" type="xs:anyURI" use="required"/>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="Password" minOccurs="0"/>
+ <xs:element ref="RestrictedPassword" minOccurs="0"/>
+ <xs:element ref="Token" minOccurs="0"/>
+ <xs:element ref="Smartcard" minOccurs="0"/>
+ <xs:element ref="ActivationPin" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="preauth" type="xs:integer" use="optional"/>
+ </xs:complexType>
+
+ <xs:group name="AuthenticatorChoiceGroup">
+ <xs:choice>
+ <xs:element ref="PreviousSession"/>
+ <xs:element ref="ResumeSession"/>
+ <xs:element ref="DigSig"/>
+ <xs:element ref="Password"/>
+ <xs:element ref="RestrictedPassword"/>
+ <xs:element ref="ZeroKnowledge"/>
+ <xs:element ref="SharedSecretChallengeResponse"/>
+ <xs:element ref="SharedSecretDynamicPlaintext"/>
+ <xs:element ref="IPAddress"/>
+ <xs:element ref="AsymmetricDecryption"/>
+ <xs:element ref="AsymmetricKeyAgreement"/>
+ <xs:element ref="SubscriberLineNumber"/>
+ <xs:element ref="UserSuffix"/>
+ <xs:element ref="ComplexAuthenticator"/>
+ </xs:choice>
+ </xs:group>
+
+ <xs:group name="AuthenticatorSequenceGroup">
+ <xs:sequence>
+ <xs:element ref="PreviousSession" minOccurs="0"/>
+ <xs:element ref="ResumeSession" minOccurs="0"/>
+ <xs:element ref="DigSig" minOccurs="0"/>
+ <xs:element ref="Password" minOccurs="0"/>
+ <xs:element ref="RestrictedPassword" minOccurs="0"/>
+ <xs:element ref="ZeroKnowledge" minOccurs="0"/>
+ <xs:element ref="SharedSecretChallengeResponse" minOccurs="0"/>
+ <xs:element ref="SharedSecretDynamicPlaintext" minOccurs="0"/>
+ <xs:element ref="IPAddress" minOccurs="0"/>
+ <xs:element ref="AsymmetricDecryption" minOccurs="0"/>
+ <xs:element ref="AsymmetricKeyAgreement" minOccurs="0"/>
+ <xs:element ref="SubscriberLineNumber" minOccurs="0"/>
+ <xs:element ref="UserSuffix" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:group>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:group ref="AuthenticatorChoiceGroup"/>
+ <xs:group ref="AuthenticatorSequenceGroup"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="ComplexAuthenticatorType">
+ <xs:sequence>
+ <xs:group ref="AuthenticatorChoiceGroup"/>
+ <xs:group ref="AuthenticatorSequenceGroup"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorTransportProtocolType">
+ <xs:sequence>
+ <xs:choice minOccurs="0">
+ <xs:element ref="HTTP"/>
+ <xs:element ref="SSL"/>
+ <xs:element ref="MobileNetworkNoEncryption"/>
+ <xs:element ref="MobileNetworkRadioEncryption"/>
+ <xs:element ref="MobileNetworkEndToEndEncryption"/>
+ <xs:element ref="WTLS"/>
+ <xs:element ref="IPSec"/>
+ <xs:element ref="PSTN"/>
+ <xs:element ref="ISDN"/>
+ <xs:element ref="ADSL"/>
+ </xs:choice>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="KeyActivationType">
+ <xs:sequence>
+ <xs:element ref="ActivationPin" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="KeySharingType">
+ <xs:attribute name="sharing" type="xs:boolean" use="required"/>
+ </xs:complexType>
+
+ <xs:complexType name="PrivateKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyActivation" minOccurs="0"/>
+ <xs:element ref="KeyStorage" minOccurs="0"/>
+ <xs:element ref="KeySharing" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="PasswordType">
+ <xs:sequence>
+ <xs:element ref="Length" minOccurs="0"/>
+ <xs:element ref="Alphabet" minOccurs="0"/>
+ <xs:element ref="Generation" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ExternalVerification" type="xs:anyURI" use="optional"/>
+ </xs:complexType>
+
+ <xs:element name="RestrictedPassword" type="RestrictedPasswordType"/>
+
+ <xs:complexType name="RestrictedPasswordType">
+ <xs:complexContent>
+ <xs:restriction base="PasswordType">
+ <xs:sequence>
+ <xs:element name="Length" type="RestrictedLengthType" minOccurs="1"/>
+ <xs:element ref="Generation" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ExternalVerification" type="xs:anyURI" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="RestrictedLengthType">
+ <xs:complexContent>
+ <xs:restriction base="LengthType">
+ <xs:attribute name="min" use="required">
+ <xs:simpleType>
+ <xs:restriction base="xs:integer">
+ <xs:minInclusive value="3"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:attribute>
+ <xs:attribute name="max" type="xs:integer" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="ActivationPinType">
+ <xs:sequence>
+ <xs:element ref="Length" minOccurs="0"/>
+ <xs:element ref="Alphabet" minOccurs="0"/>
+ <xs:element ref="Generation" minOccurs="0"/>
+ <xs:element ref="ActivationLimit" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:element name="Alphabet" type="AlphabetType"/>
+ <xs:complexType name="AlphabetType">
+ <xs:attribute name="requiredChars" type="xs:string" use="required"/>
+ <xs:attribute name="excludedChars" type="xs:string" use="optional"/>
+ <xs:attribute name="case" type="xs:string" use="optional"/>
+ </xs:complexType>
+
+ <xs:complexType name="TokenType">
+ <xs:sequence>
+ <xs:element ref="TimeSyncToken"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:simpleType name="DeviceTypeType">
+ <xs:restriction base="xs:NMTOKEN">
+ <xs:enumeration value="hardware"/>
+ <xs:enumeration value="software"/>
+ </xs:restriction>
+ </xs:simpleType>
+
+ <xs:simpleType name="booleanType">
+ <xs:restriction base="xs:NMTOKEN">
+ <xs:enumeration value="true"/>
+ <xs:enumeration value="false"/>
+ </xs:restriction>
+ </xs:simpleType>
+
+ <xs:complexType name="TimeSyncTokenType">
+ <xs:attribute name="DeviceType" type="DeviceTypeType" use="required"/>
+ <xs:attribute name="SeedLength" type="xs:integer" use="required"/>
+ <xs:attribute name="DeviceInHand" type="booleanType" use="required"/>
+ </xs:complexType>
+
+ <xs:complexType name="ActivationLimitType">
+ <xs:choice>
+ <xs:element ref="ActivationLimitDuration"/>
+ <xs:element ref="ActivationLimitUsages"/>
+ <xs:element ref="ActivationLimitSession"/>
+ </xs:choice>
+ </xs:complexType>
+
+ <xs:element name="ActivationLimitDuration" type="ActivationLimitDurationType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Key Activation Limit is
+ defined as a specific duration of time.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="ActivationLimitUsages" type="ActivationLimitUsagesType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Key Activation Limit is
+ defined as a number of usages.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:element name="ActivationLimitSession" type="ActivationLimitSessionType">
+ <xs:annotation>
+ <xs:documentation>
+ This element indicates that the Key Activation Limit is
+ the session.
+ </xs:documentation>
+ </xs:annotation>
+ </xs:element>
+
+ <xs:complexType name="ActivationLimitDurationType">
+ <xs:attribute name="duration" type="xs:duration" use="required"/>
+ </xs:complexType>
+
+ <xs:complexType name="ActivationLimitUsagesType">
+ <xs:attribute name="number" type="xs:integer" use="required"/>
+ </xs:complexType>
+
+ <xs:complexType name="ActivationLimitSessionType"/>
+
+ <xs:complexType name="LengthType">
+ <xs:attribute name="min" type="xs:integer" use="required"/>
+ <xs:attribute name="max" type="xs:integer" use="optional"/>
+ </xs:complexType>
+
+ <xs:simpleType name="mediumType">
+ <xs:restriction base="xs:NMTOKEN">
+ <xs:enumeration value="memory"/>
+ <xs:enumeration value="smartcard"/>
+ <xs:enumeration value="token"/>
+ <xs:enumeration value="MobileDevice"/>
+ <xs:enumeration value="MobileAuthCard"/>
+ </xs:restriction>
+ </xs:simpleType>
+
+ <xs:complexType name="KeyStorageType">
+ <xs:attribute name="medium" type="mediumType" use="required"/>
+ </xs:complexType>
+
+ <xs:complexType name="SecretKeyProtectionType">
+ <xs:sequence>
+ <xs:element ref="KeyActivation" minOccurs="0"/>
+ <xs:element ref="KeyStorage" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="SecurityAuditType">
+ <xs:sequence>
+ <xs:element ref="SwitchAudit" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:complexType name="ExtensionOnlyType">
+ <xs:sequence>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+ <xs:element name="Extension" type="ExtensionType"/>
+
+ <xs:complexType name="ExtensionType">
+ <xs:sequence>
+ <xs:any namespace="##other" processContents="lax" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:complexType>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-x509-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-x509-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-x509-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,83 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:X509"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:X509"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:X509
+ Document identifier: saml-schema-authn-context-x509-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="RestrictedPassword"/>
+ </xs:sequence>
+ <xs:attribute name="preauth" type="xs:integer" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="DigSig"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PublicKeyType">
+ <xs:complexContent>
+ <xs:restriction base="PublicKeyType">
+ <xs:attribute name="keyValidation" type="xs:anyURI" fixed="urn:oasis:names:tc:SAML:2.0:ac:classes:X509"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-xmldsig-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-xmldsig-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-authn-context-xmldsig-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,83 @@
+<?xml version="1.0" encoding="UTF-8"?>
+
+<xs:schema targetNamespace="urn:oasis:names:tc:SAML:2.0:ac:classes:XMLDSig"
+ xmlns:xs="http://www.w3.org/2001/XMLSchema"
+ xmlns="urn:oasis:names:tc:SAML:2.0:ac:classes:XMLDSig"
+ finalDefault="extension"
+ blockDefault="substitution"
+ version="2.0">
+
+ <xs:redefine schemaLocation="saml-schema-authn-context-types-2.0.xsd">
+
+ <xs:annotation>
+ <xs:documentation>
+ Class identifier: urn:oasis:names:tc:SAML:2.0:ac:classes:XMLDSig
+ Document identifier: saml-schema-authn-context-xmldsig-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ New authentication context class schema for SAML V2.0.
+ </xs:documentation>
+ </xs:annotation>
+
+ <xs:complexType name="AuthnContextDeclarationBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnContextDeclarationBaseType">
+ <xs:sequence>
+ <xs:element ref="Identification" minOccurs="0"/>
+ <xs:element ref="TechnicalProtection" minOccurs="0"/>
+ <xs:element ref="OperationalProtection" minOccurs="0"/>
+ <xs:element ref="AuthnMethod"/>
+ <xs:element ref="GoverningAgreements" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ <xs:attribute name="ID" type="xs:ID" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthnMethodBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthnMethodBaseType">
+ <xs:sequence>
+ <xs:element ref="PrincipalAuthenticationMechanism"/>
+ <xs:element ref="Authenticator"/>
+ <xs:element ref="AuthenticatorTransportProtocol" minOccurs="0"/>
+ <xs:element ref="Extension" minOccurs="0" maxOccurs="unbounded"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PrincipalAuthenticationMechanismType">
+ <xs:complexContent>
+ <xs:restriction base="PrincipalAuthenticationMechanismType">
+ <xs:sequence>
+ <xs:element ref="RestrictedPassword"/>
+ </xs:sequence>
+ <xs:attribute name="preauth" type="xs:integer" use="optional"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="AuthenticatorBaseType">
+ <xs:complexContent>
+ <xs:restriction base="AuthenticatorBaseType">
+ <xs:sequence>
+ <xs:element ref="DigSig"/>
+ </xs:sequence>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ <xs:complexType name="PublicKeyType">
+ <xs:complexContent>
+ <xs:restriction base="PublicKeyType">
+ <xs:attribute name="keyValidation" type="xs:anyURI" fixed="urn:ietf:rfc:3075"/>
+ </xs:restriction>
+ </xs:complexContent>
+ </xs:complexType>
+
+ </xs:redefine>
+
+</xs:schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-dce-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-dce-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-dce-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,29 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<schema targetNamespace="urn:oasis:names:tc:SAML:2.0:profiles:attribute:DCE"
+ xmlns:dce="urn:oasis:names:tc:SAML:2.0:profiles:attribute:DCE"
+ xmlns="http://www.w3.org/2001/XMLSchema"
+ elementFormDefault="unqualified"
+ attributeFormDefault="unqualified"
+ blockDefault="substitution"
+ version="2.0">
+ <annotation>
+ <documentation>
+ Document identifier: saml-schema-dce-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ Custom schema for DCE attribute profile, first published in SAML 2.0.
+ </documentation>
+ </annotation>
+ <complexType name="DCEValueType">
+ <simpleContent>
+ <extension base="anyURI">
+ <attribute ref="dce:Realm" use="optional"/>
+ <attribute ref="dce:FriendlyName" use="optional"/>
+ </extension>
+ </simpleContent>
+ </complexType>
+ <attribute name="Realm" type="anyURI"/>
+ <attribute name="FriendlyName" type="string"/>
+</schema>
+
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-ecp-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-ecp-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-ecp-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,57 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<schema
+ targetNamespace="urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp"
+ xmlns="http://www.w3.org/2001/XMLSchema"
+ xmlns:ecp="urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp"
+ xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
+ xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
+ xmlns:S="http://schemas.xmlsoap.org/soap/envelope/"
+ elementFormDefault="unqualified"
+ attributeFormDefault="unqualified"
+ blockDefault="substitution"
+ version="2.0">
+ <import namespace="urn:oasis:names:tc:SAML:2.0:protocol"
+ schemaLocation="saml-schema-protocol-2.0.xsd"/>
+ <import namespace="urn:oasis:names:tc:SAML:2.0:assertion"
+ schemaLocation="saml-schema-assertion-2.0.xsd"/>
+ <import namespace="http://schemas.xmlsoap.org/soap/envelope/"
+ schemaLocation="http://schemas.xmlsoap.org/soap/envelope/"/>
+ <annotation>
+ <documentation>
+ Document identifier: saml-schema-ecp-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ Custom schema for ECP profile, first published in SAML 2.0.
+ </documentation>
+ </annotation>
+
+ <element name="Request" type="ecp:RequestType"/>
+ <complexType name="RequestType">
+ <sequence>
+ <element ref="saml:Issuer"/>
+ <element ref="samlp:IDPList" minOccurs="0"/>
+ </sequence>
+ <attribute ref="S:mustUnderstand" use="required"/>
+ <attribute ref="S:actor" use="required"/>
+ <attribute name="ProviderName" type="string" use="optional"/>
+ <attribute name="IsPassive" type="boolean" use="optional"/>
+ </complexType>
+
+ <element name="Response" type="ecp:ResponseType"/>
+ <complexType name="ResponseType">
+ <attribute ref="S:mustUnderstand" use="required"/>
+ <attribute ref="S:actor" use="required"/>
+ <attribute name="AssertionConsumerServiceURL" type="anyURI" use="required"/>
+ </complexType>
+
+ <element name="RelayState" type="ecp:RelayStateType"/>
+ <complexType name="RelayStateType">
+ <simpleContent>
+ <extension base="string">
+ <attribute ref="S:mustUnderstand" use="required"/>
+ <attribute ref="S:actor" use="required"/>
+ </extension>
+ </simpleContent>
+ </complexType>
+</schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-metadata-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-metadata-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-metadata-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,337 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<schema
+ targetNamespace="urn:oasis:names:tc:SAML:2.0:metadata"
+ xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
+ xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
+ xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"
+ xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
+ xmlns="http://www.w3.org/2001/XMLSchema"
+ elementFormDefault="unqualified"
+ attributeFormDefault="unqualified"
+ blockDefault="substitution"
+ version="2.0">
+ <import namespace="http://www.w3.org/2000/09/xmldsig#"
+ schemaLocation="http://www.w3.org/TR/2002/REC-xmldsig-core-20020212/xmldsig-core-schema.xsd"/>
+ <import namespace="http://www.w3.org/2001/04/xmlenc#"
+ schemaLocation="http://www.w3.org/TR/2002/REC-xmlenc-core-20021210/xenc-schema.xsd"/>
+ <import namespace="urn:oasis:names:tc:SAML:2.0:assertion"
+ schemaLocation="saml-schema-assertion-2.0.xsd"/>
+ <import namespace="http://www.w3.org/XML/1998/namespace"
+ schemaLocation="http://www.w3.org/2001/xml.xsd"/>
+ <annotation>
+ <documentation>
+ Document identifier: saml-schema-metadata-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ Schema for SAML metadata, first published in SAML 2.0.
+ </documentation>
+ </annotation>
+
+ <simpleType name="entityIDType">
+ <restriction base="anyURI">
+ <maxLength value="1024"/>
+ </restriction>
+ </simpleType>
+ <complexType name="localizedNameType">
+ <simpleContent>
+ <extension base="string">
+ <attribute ref="xml:lang" use="required"/>
+ </extension>
+ </simpleContent>
+ </complexType>
+ <complexType name="localizedURIType">
+ <simpleContent>
+ <extension base="anyURI">
+ <attribute ref="xml:lang" use="required"/>
+ </extension>
+ </simpleContent>
+ </complexType>
+
+ <element name="Extensions" type="md:ExtensionsType"/>
+ <complexType final="#all" name="ExtensionsType">
+ <sequence>
+ <any namespace="##other" processContents="lax" maxOccurs="unbounded"/>
+ </sequence>
+ </complexType>
+
+ <complexType name="EndpointType">
+ <sequence>
+ <any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="Binding" type="anyURI" use="required"/>
+ <attribute name="Location" type="anyURI" use="required"/>
+ <attribute name="ResponseLocation" type="anyURI" use="optional"/>
+ <anyAttribute namespace="##other" processContents="lax"/>
+ </complexType>
+
+ <complexType name="IndexedEndpointType">
+ <complexContent>
+ <extension base="md:EndpointType">
+ <attribute name="index" type="unsignedShort" use="required"/>
+ <attribute name="isDefault" type="boolean" use="optional"/>
+ </extension>
+ </complexContent>
+ </complexType>
+
+ <element name="EntitiesDescriptor" type="md:EntitiesDescriptorType"/>
+ <complexType name="EntitiesDescriptorType">
+ <sequence>
+ <element ref="ds:Signature" minOccurs="0"/>
+ <element ref="md:Extensions" minOccurs="0"/>
+ <choice minOccurs="1" maxOccurs="unbounded">
+ <element ref="md:EntityDescriptor"/>
+ <element ref="md:EntitiesDescriptor"/>
+ </choice>
+ </sequence>
+ <attribute name="validUntil" type="dateTime" use="optional"/>
+ <attribute name="cacheDuration" type="duration" use="optional"/>
+ <attribute name="ID" type="ID" use="optional"/>
+ <attribute name="Name" type="string" use="optional"/>
+ </complexType>
+
+ <element name="EntityDescriptor" type="md:EntityDescriptorType"/>
+ <complexType name="EntityDescriptorType">
+ <sequence>
+ <element ref="ds:Signature" minOccurs="0"/>
+ <element ref="md:Extensions" minOccurs="0"/>
+ <choice>
+ <choice maxOccurs="unbounded">
+ <element ref="md:RoleDescriptor"/>
+ <element ref="md:IDPSSODescriptor"/>
+ <element ref="md:SPSSODescriptor"/>
+ <element ref="md:AuthnAuthorityDescriptor"/>
+ <element ref="md:AttributeAuthorityDescriptor"/>
+ <element ref="md:PDPDescriptor"/>
+ </choice>
+ <element ref="md:AffiliationDescriptor"/>
+ </choice>
+ <element ref="md:Organization" minOccurs="0"/>
+ <element ref="md:ContactPerson" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:AdditionalMetadataLocation" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="entityID" type="md:entityIDType" use="required"/>
+ <attribute name="validUntil" type="dateTime" use="optional"/>
+ <attribute name="cacheDuration" type="duration" use="optional"/>
+ <attribute name="ID" type="ID" use="optional"/>
+ <anyAttribute namespace="##other" processContents="lax"/>
+ </complexType>
+
+ <element name="Organization" type="md:OrganizationType"/>
+ <complexType name="OrganizationType">
+ <sequence>
+ <element ref="md:Extensions" minOccurs="0"/>
+ <element ref="md:OrganizationName" maxOccurs="unbounded"/>
+ <element ref="md:OrganizationDisplayName" maxOccurs="unbounded"/>
+ <element ref="md:OrganizationURL" maxOccurs="unbounded"/>
+ </sequence>
+ <anyAttribute namespace="##other" processContents="lax"/>
+ </complexType>
+ <element name="OrganizationName" type="md:localizedNameType"/>
+ <element name="OrganizationDisplayName" type="md:localizedNameType"/>
+ <element name="OrganizationURL" type="md:localizedURIType"/>
+ <element name="ContactPerson" type="md:ContactType"/>
+ <complexType name="ContactType">
+ <sequence>
+ <element ref="md:Extensions" minOccurs="0"/>
+ <element ref="md:Company" minOccurs="0"/>
+ <element ref="md:GivenName" minOccurs="0"/>
+ <element ref="md:SurName" minOccurs="0"/>
+ <element ref="md:EmailAddress" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:TelephoneNumber" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="contactType" type="md:ContactTypeType" use="required"/>
+ <anyAttribute namespace="##other" processContents="lax"/>
+ </complexType>
+ <element name="Company" type="string"/>
+ <element name="GivenName" type="string"/>
+ <element name="SurName" type="string"/>
+ <element name="EmailAddress" type="anyURI"/>
+ <element name="TelephoneNumber" type="string"/>
+ <simpleType name="ContactTypeType">
+ <restriction base="string">
+ <enumeration value="technical"/>
+ <enumeration value="support"/>
+ <enumeration value="administrative"/>
+ <enumeration value="billing"/>
+ <enumeration value="other"/>
+ </restriction>
+ </simpleType>
+
+ <element name="AdditionalMetadataLocation" type="md:AdditionalMetadataLocationType"/>
+ <complexType name="AdditionalMetadataLocationType">
+ <simpleContent>
+ <extension base="anyURI">
+ <attribute name="namespace" type="anyURI" use="required"/>
+ </extension>
+ </simpleContent>
+ </complexType>
+
+ <element name="RoleDescriptor" type="md:RoleDescriptorType"/>
+ <complexType name="RoleDescriptorType" abstract="true">
+ <sequence>
+ <element ref="ds:Signature" minOccurs="0"/>
+ <element ref="md:Extensions" minOccurs="0"/>
+ <element ref="md:KeyDescriptor" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:Organization" minOccurs="0"/>
+ <element ref="md:ContactPerson" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="ID" type="ID" use="optional"/>
+ <attribute name="validUntil" type="dateTime" use="optional"/>
+ <attribute name="cacheDuration" type="duration" use="optional"/>
+ <attribute name="protocolSupportEnumeration" type="md:anyURIListType" use="required"/>
+ <attribute name="errorURL" type="anyURI" use="optional"/>
+ <anyAttribute namespace="##other" processContents="lax"/>
+ </complexType>
+ <simpleType name="anyURIListType">
+ <list itemType="anyURI"/>
+ </simpleType>
+
+ <element name="KeyDescriptor" type="md:KeyDescriptorType"/>
+ <complexType name="KeyDescriptorType">
+ <sequence>
+ <element ref="ds:KeyInfo"/>
+ <element ref="md:EncryptionMethod" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="use" type="md:KeyTypes" use="optional"/>
+ </complexType>
+ <simpleType name="KeyTypes">
+ <restriction base="string">
+ <enumeration value="encryption"/>
+ <enumeration value="signing"/>
+ </restriction>
+ </simpleType>
+ <element name="EncryptionMethod" type="xenc:EncryptionMethodType"/>
+
+ <complexType name="SSODescriptorType" abstract="true">
+ <complexContent>
+ <extension base="md:RoleDescriptorType">
+ <sequence>
+ <element ref="md:ArtifactResolutionService" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:SingleLogoutService" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:ManageNameIDService" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:NameIDFormat" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="ArtifactResolutionService" type="md:IndexedEndpointType"/>
+ <element name="SingleLogoutService" type="md:EndpointType"/>
+ <element name="ManageNameIDService" type="md:EndpointType"/>
+ <element name="NameIDFormat" type="anyURI"/>
+
+ <element name="IDPSSODescriptor" type="md:IDPSSODescriptorType"/>
+ <complexType name="IDPSSODescriptorType">
+ <complexContent>
+ <extension base="md:SSODescriptorType">
+ <sequence>
+ <element ref="md:SingleSignOnService" maxOccurs="unbounded"/>
+ <element ref="md:NameIDMappingService" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:AssertionIDRequestService" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:AttributeProfile" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="saml:Attribute" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="WantAuthnRequestsSigned" type="boolean" use="optional"/>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="SingleSignOnService" type="md:EndpointType"/>
+ <element name="NameIDMappingService" type="md:EndpointType"/>
+ <element name="AssertionIDRequestService" type="md:EndpointType"/>
+ <element name="AttributeProfile" type="anyURI"/>
+
+ <element name="SPSSODescriptor" type="md:SPSSODescriptorType"/>
+ <complexType name="SPSSODescriptorType">
+ <complexContent>
+ <extension base="md:SSODescriptorType">
+ <sequence>
+ <element ref="md:AssertionConsumerService" maxOccurs="unbounded"/>
+ <element ref="md:AttributeConsumingService" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="AuthnRequestsSigned" type="boolean" use="optional"/>
+ <attribute name="WantAssertionsSigned" type="boolean" use="optional"/>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="AssertionConsumerService" type="md:IndexedEndpointType"/>
+ <element name="AttributeConsumingService" type="md:AttributeConsumingServiceType"/>
+ <complexType name="AttributeConsumingServiceType">
+ <sequence>
+ <element ref="md:ServiceName" maxOccurs="unbounded"/>
+ <element ref="md:ServiceDescription" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:RequestedAttribute" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="index" type="unsignedShort" use="required"/>
+ <attribute name="isDefault" type="boolean" use="optional"/>
+ </complexType>
+ <element name="ServiceName" type="md:localizedNameType"/>
+ <element name="ServiceDescription" type="md:localizedNameType"/>
+ <element name="RequestedAttribute" type="md:RequestedAttributeType"/>
+ <complexType name="RequestedAttributeType">
+ <complexContent>
+ <extension base="saml:AttributeType">
+ <attribute name="isRequired" type="boolean" use="optional"/>
+ </extension>
+ </complexContent>
+ </complexType>
+
+ <element name="AuthnAuthorityDescriptor" type="md:AuthnAuthorityDescriptorType"/>
+ <complexType name="AuthnAuthorityDescriptorType">
+ <complexContent>
+ <extension base="md:RoleDescriptorType">
+ <sequence>
+ <element ref="md:AuthnQueryService" maxOccurs="unbounded"/>
+ <element ref="md:AssertionIDRequestService" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:NameIDFormat" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="AuthnQueryService" type="md:EndpointType"/>
+
+ <element name="PDPDescriptor" type="md:PDPDescriptorType"/>
+ <complexType name="PDPDescriptorType">
+ <complexContent>
+ <extension base="md:RoleDescriptorType">
+ <sequence>
+ <element ref="md:AuthzService" maxOccurs="unbounded"/>
+ <element ref="md:AssertionIDRequestService" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:NameIDFormat" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="AuthzService" type="md:EndpointType"/>
+
+ <element name="AttributeAuthorityDescriptor" type="md:AttributeAuthorityDescriptorType"/>
+ <complexType name="AttributeAuthorityDescriptorType">
+ <complexContent>
+ <extension base="md:RoleDescriptorType">
+ <sequence>
+ <element ref="md:AttributeService" maxOccurs="unbounded"/>
+ <element ref="md:AssertionIDRequestService" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:NameIDFormat" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="md:AttributeProfile" minOccurs="0" maxOccurs="unbounded"/>
+ <element ref="saml:Attribute" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="AttributeService" type="md:EndpointType"/>
+
+ <element name="AffiliationDescriptor" type="md:AffiliationDescriptorType"/>
+ <complexType name="AffiliationDescriptorType">
+ <sequence>
+ <element ref="ds:Signature" minOccurs="0"/>
+ <element ref="md:Extensions" minOccurs="0"/>
+ <element ref="md:AffiliateMember" maxOccurs="unbounded"/>
+ <element ref="md:KeyDescriptor" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="affiliationOwnerID" type="md:entityIDType" use="required"/>
+ <attribute name="validUntil" type="dateTime" use="optional"/>
+ <attribute name="cacheDuration" type="duration" use="optional"/>
+ <attribute name="ID" type="ID" use="optional"/>
+ <anyAttribute namespace="##other" processContents="lax"/>
+ </complexType>
+ <element name="AffiliateMember" type="md:entityIDType"/>
+</schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-protocol-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-protocol-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-protocol-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,302 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<schema
+ targetNamespace="urn:oasis:names:tc:SAML:2.0:protocol"
+ xmlns="http://www.w3.org/2001/XMLSchema"
+ xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
+ xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
+ xmlns:ds="http://www.w3.org/2000/09/xmldsig#"
+ elementFormDefault="unqualified"
+ attributeFormDefault="unqualified"
+ blockDefault="substitution"
+ version="2.0">
+ <import namespace="urn:oasis:names:tc:SAML:2.0:assertion"
+ schemaLocation="saml-schema-assertion-2.0.xsd"/>
+ <import namespace="http://www.w3.org/2000/09/xmldsig#"
+ schemaLocation="http://www.w3.org/TR/2002/REC-xmldsig-core-20020212/xmldsig-core-schema.xsd"/>
+ <annotation>
+ <documentation>
+ Document identifier: saml-schema-protocol-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V1.0 (November, 2002):
+ Initial Standard Schema.
+ V1.1 (September, 2003):
+ Updates within the same V1.0 namespace.
+ V2.0 (March, 2005):
+ New protocol schema based in a SAML V2.0 namespace.
+ </documentation>
+ </annotation>
+ <complexType name="RequestAbstractType" abstract="true">
+ <sequence>
+ <element ref="saml:Issuer" minOccurs="0"/>
+ <element ref="ds:Signature" minOccurs="0"/>
+ <element ref="samlp:Extensions" minOccurs="0"/>
+ </sequence>
+ <attribute name="ID" type="ID" use="required"/>
+ <attribute name="Version" type="string" use="required"/>
+ <attribute name="IssueInstant" type="dateTime" use="required"/>
+ <attribute name="Destination" type="anyURI" use="optional"/>
+ <attribute name="Consent" type="anyURI" use="optional"/>
+ </complexType>
+ <element name="Extensions" type="samlp:ExtensionsType"/>
+ <complexType name="ExtensionsType">
+ <sequence>
+ <any namespace="##other" processContents="lax" maxOccurs="unbounded"/>
+ </sequence>
+ </complexType>
+ <complexType name="StatusResponseType">
+ <sequence>
+ <element ref="saml:Issuer" minOccurs="0"/>
+ <element ref="ds:Signature" minOccurs="0"/>
+ <element ref="samlp:Extensions" minOccurs="0"/>
+ <element ref="samlp:Status"/>
+ </sequence>
+ <attribute name="ID" type="ID" use="required"/>
+ <attribute name="InResponseTo" type="NCName" use="optional"/>
+ <attribute name="Version" type="string" use="required"/>
+ <attribute name="IssueInstant" type="dateTime" use="required"/>
+ <attribute name="Destination" type="anyURI" use="optional"/>
+ <attribute name="Consent" type="anyURI" use="optional"/>
+ </complexType>
+ <element name="Status" type="samlp:StatusType"/>
+ <complexType name="StatusType">
+ <sequence>
+ <element ref="samlp:StatusCode"/>
+ <element ref="samlp:StatusMessage" minOccurs="0"/>
+ <element ref="samlp:StatusDetail" minOccurs="0"/>
+ </sequence>
+ </complexType>
+ <element name="StatusCode" type="samlp:StatusCodeType"/>
+ <complexType name="StatusCodeType">
+ <sequence>
+ <element ref="samlp:StatusCode" minOccurs="0"/>
+ </sequence>
+ <attribute name="Value" type="anyURI" use="required"/>
+ </complexType>
+ <element name="StatusMessage" type="string"/>
+ <element name="StatusDetail" type="samlp:StatusDetailType"/>
+ <complexType name="StatusDetailType">
+ <sequence>
+ <any namespace="##any" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ </complexType>
+ <element name="AssertionIDRequest" type="samlp:AssertionIDRequestType"/>
+ <complexType name="AssertionIDRequestType">
+ <complexContent>
+ <extension base="samlp:RequestAbstractType">
+ <sequence>
+ <element ref="saml:AssertionIDRef" maxOccurs="unbounded"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="SubjectQuery" type="samlp:SubjectQueryAbstractType"/>
+ <complexType name="SubjectQueryAbstractType" abstract="true">
+ <complexContent>
+ <extension base="samlp:RequestAbstractType">
+ <sequence>
+ <element ref="saml:Subject"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="AuthnQuery" type="samlp:AuthnQueryType"/>
+ <complexType name="AuthnQueryType">
+ <complexContent>
+ <extension base="samlp:SubjectQueryAbstractType">
+ <sequence>
+ <element ref="samlp:RequestedAuthnContext" minOccurs="0"/>
+ </sequence>
+ <attribute name="SessionIndex" type="string" use="optional"/>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="RequestedAuthnContext" type="samlp:RequestedAuthnContextType"/>
+ <complexType name="RequestedAuthnContextType">
+ <choice>
+ <element ref="saml:AuthnContextClassRef" maxOccurs="unbounded"/>
+ <element ref="saml:AuthnContextDeclRef" maxOccurs="unbounded"/>
+ </choice>
+ <attribute name="Comparison" type="samlp:AuthnContextComparisonType" use="optional"/>
+ </complexType>
+ <simpleType name="AuthnContextComparisonType">
+ <restriction base="string">
+ <enumeration value="exact"/>
+ <enumeration value="minimum"/>
+ <enumeration value="maximum"/>
+ <enumeration value="better"/>
+ </restriction>
+ </simpleType>
+ <element name="AttributeQuery" type="samlp:AttributeQueryType"/>
+ <complexType name="AttributeQueryType">
+ <complexContent>
+ <extension base="samlp:SubjectQueryAbstractType">
+ <sequence>
+ <element ref="saml:Attribute" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="AuthzDecisionQuery" type="samlp:AuthzDecisionQueryType"/>
+ <complexType name="AuthzDecisionQueryType">
+ <complexContent>
+ <extension base="samlp:SubjectQueryAbstractType">
+ <sequence>
+ <element ref="saml:Action" maxOccurs="unbounded"/>
+ <element ref="saml:Evidence" minOccurs="0"/>
+ </sequence>
+ <attribute name="Resource" type="anyURI" use="required"/>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="AuthnRequest" type="samlp:AuthnRequestType"/>
+ <complexType name="AuthnRequestType">
+ <complexContent>
+ <extension base="samlp:RequestAbstractType">
+ <sequence>
+ <element ref="saml:Subject" minOccurs="0"/>
+ <element ref="samlp:NameIDPolicy" minOccurs="0"/>
+ <element ref="saml:Conditions" minOccurs="0"/>
+ <element ref="samlp:RequestedAuthnContext" minOccurs="0"/>
+ <element ref="samlp:Scoping" minOccurs="0"/>
+ </sequence>
+ <attribute name="ForceAuthn" type="boolean" use="optional"/>
+ <attribute name="IsPassive" type="boolean" use="optional"/>
+ <attribute name="ProtocolBinding" type="anyURI" use="optional"/>
+ <attribute name="AssertionConsumerServiceIndex" type="unsignedShort" use="optional"/>
+ <attribute name="AssertionConsumerServiceURL" type="anyURI" use="optional"/>
+ <attribute name="AttributeConsumingServiceIndex" type="unsignedShort" use="optional"/>
+ <attribute name="ProviderName" type="string" use="optional"/>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="NameIDPolicy" type="samlp:NameIDPolicyType"/>
+ <complexType name="NameIDPolicyType">
+ <attribute name="Format" type="anyURI" use="optional"/>
+ <attribute name="SPNameQualifier" type="string" use="optional"/>
+ <attribute name="AllowCreate" type="boolean" use="optional"/>
+ </complexType>
+ <element name="Scoping" type="samlp:ScopingType"/>
+ <complexType name="ScopingType">
+ <sequence>
+ <element ref="samlp:IDPList" minOccurs="0"/>
+ <element ref="samlp:RequesterID" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="ProxyCount" type="nonNegativeInteger" use="optional"/>
+ </complexType>
+ <element name="RequesterID" type="anyURI"/>
+ <element name="IDPList" type="samlp:IDPListType"/>
+ <complexType name="IDPListType">
+ <sequence>
+ <element ref="samlp:IDPEntry" maxOccurs="unbounded"/>
+ <element ref="samlp:GetComplete" minOccurs="0"/>
+ </sequence>
+ </complexType>
+ <element name="IDPEntry" type="samlp:IDPEntryType"/>
+ <complexType name="IDPEntryType">
+ <attribute name="ProviderID" type="anyURI" use="required"/>
+ <attribute name="Name" type="string" use="optional"/>
+ <attribute name="Loc" type="anyURI" use="optional"/>
+ </complexType>
+ <element name="GetComplete" type="anyURI"/>
+ <element name="Response" type="samlp:ResponseType"/>
+ <complexType name="ResponseType">
+ <complexContent>
+ <extension base="samlp:StatusResponseType">
+ <choice minOccurs="0" maxOccurs="unbounded">
+ <element ref="saml:Assertion"/>
+ <element ref="saml:EncryptedAssertion"/>
+ </choice>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="ArtifactResolve" type="samlp:ArtifactResolveType"/>
+ <complexType name="ArtifactResolveType">
+ <complexContent>
+ <extension base="samlp:RequestAbstractType">
+ <sequence>
+ <element ref="samlp:Artifact"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="Artifact" type="string"/>
+ <element name="ArtifactResponse" type="samlp:ArtifactResponseType"/>
+ <complexType name="ArtifactResponseType">
+ <complexContent>
+ <extension base="samlp:StatusResponseType">
+ <sequence>
+ <any namespace="##any" processContents="lax" minOccurs="0"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="ManageNameIDRequest" type="samlp:ManageNameIDRequestType"/>
+ <complexType name="ManageNameIDRequestType">
+ <complexContent>
+ <extension base="samlp:RequestAbstractType">
+ <sequence>
+ <choice>
+ <element ref="saml:NameID"/>
+ <element ref="saml:EncryptedID"/>
+ </choice>
+ <choice>
+ <element ref="samlp:NewID"/>
+ <element ref="samlp:NewEncryptedID"/>
+ <element ref="samlp:Terminate"/>
+ </choice>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="NewID" type="string"/>
+ <element name="NewEncryptedID" type="saml:EncryptedElementType"/>
+ <element name="Terminate" type="samlp:TerminateType"/>
+ <complexType name="TerminateType"/>
+ <element name="ManageNameIDResponse" type="samlp:StatusResponseType"/>
+ <element name="LogoutRequest" type="samlp:LogoutRequestType"/>
+ <complexType name="LogoutRequestType">
+ <complexContent>
+ <extension base="samlp:RequestAbstractType">
+ <sequence>
+ <choice>
+ <element ref="saml:BaseID"/>
+ <element ref="saml:NameID"/>
+ <element ref="saml:EncryptedID"/>
+ </choice>
+ <element ref="samlp:SessionIndex" minOccurs="0" maxOccurs="unbounded"/>
+ </sequence>
+ <attribute name="Reason" type="string" use="optional"/>
+ <attribute name="NotOnOrAfter" type="dateTime" use="optional"/>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="SessionIndex" type="string"/>
+ <element name="LogoutResponse" type="samlp:StatusResponseType"/>
+ <element name="NameIDMappingRequest" type="samlp:NameIDMappingRequestType"/>
+ <complexType name="NameIDMappingRequestType">
+ <complexContent>
+ <extension base="samlp:RequestAbstractType">
+ <sequence>
+ <choice>
+ <element ref="saml:BaseID"/>
+ <element ref="saml:NameID"/>
+ <element ref="saml:EncryptedID"/>
+ </choice>
+ <element ref="samlp:NameIDPolicy"/>
+ </sequence>
+ </extension>
+ </complexContent>
+ </complexType>
+ <element name="NameIDMappingResponse" type="samlp:NameIDMappingResponseType"/>
+ <complexType name="NameIDMappingResponseType">
+ <complexContent>
+ <extension base="samlp:StatusResponseType">
+ <choice>
+ <element ref="saml:NameID"/>
+ <element ref="saml:EncryptedID"/>
+ </choice>
+ </extension>
+ </complexContent>
+ </complexType>
+</schema>
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-x500-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-x500-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-x500-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,20 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<schema
+ targetNamespace="urn:oasis:names:tc:SAML:2.0:profiles:attribute:X500"
+ xmlns="http://www.w3.org/2001/XMLSchema"
+ elementFormDefault="unqualified"
+ attributeFormDefault="unqualified"
+ blockDefault="substitution"
+ version="2.0">
+ <annotation>
+ <documentation>
+ Document identifier: saml-schema-x500-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ Custom schema for X.500 attribute profile, first published in SAML 2.0.
+ </documentation>
+ </annotation>
+ <attribute name="Encoding" type="string"/>
+</schema>
+
Added: identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-xacml-2.0.xsd
===================================================================
--- identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-xacml-2.0.xsd (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/main/resources/schema/saml-schema-xacml-2.0.xsd 2008-12-09 16:12:35 UTC (rev 128)
@@ -0,0 +1,19 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<schema
+ targetNamespace="urn:oasis:names:tc:SAML:2.0:profiles:attribute:XACML"
+ xmlns="http://www.w3.org/2001/XMLSchema"
+ elementFormDefault="unqualified"
+ attributeFormDefault="unqualified"
+ blockDefault="substitution"
+ version="2.0">
+ <annotation>
+ <documentation>
+ Document identifier: saml-schema-xacml-2.0
+ Location: http://docs.oasis-open.org/security/saml/v2.0/
+ Revision history:
+ V2.0 (March, 2005):
+ Custom schema for XACML attribute profile, first published in SAML 2.0.
+ </documentation>
+ </annotation>
+ <attribute name="DataType" type="anyURI"/>
+</schema>
17 years, 7 months
JBoss Identity SVN: r127 - in identity-federation/trunk/identity-opensaml/src/test: java and 14 other directories.
by jboss-identity-commits@lists.jboss.org
Author: anil.saldhana(a)jboss.com
Date: 2008-12-09 11:10:21 -0500 (Tue, 09 Dec 2008)
New Revision: 127
Added:
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml/v2/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml/v2/SAML2AuthnRequestUnitTestCase.java
identity-federation/trunk/identity-opensaml/src/test/resources/saml/
identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/
identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest/
identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest/samlAuthnRequestExample.xml
identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest/samlAuthnRequestWithSignature.xml
Modified:
identity-federation/trunk/identity-opensaml/src/test/
identity-federation/trunk/identity-opensaml/src/test/java/
identity-federation/trunk/identity-opensaml/src/test/java/org/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/opensaml/
identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/opensaml/saml2/
identity-federation/trunk/identity-opensaml/src/test/resources/
identity-federation/trunk/identity-opensaml/src/test/resources/endorsed/
Log:
tests
Property changes on: identity-federation/trunk/identity-opensaml/src/test
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/opensaml
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/opensaml/saml2
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Added: identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml/v2/SAML2AuthnRequestUnitTestCase.java
===================================================================
--- identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml/v2/SAML2AuthnRequestUnitTestCase.java (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/test/java/org/jboss/test/identity/federation/saml/v2/SAML2AuthnRequestUnitTestCase.java 2008-12-09 16:10:21 UTC (rev 127)
@@ -0,0 +1,105 @@
+/*
+ * JBoss, Home of Professional Open Source.
+ * Copyright 2008, Red Hat Middleware LLC, and individual contributors
+ * as indicated by the @author tags. See the copyright.txt file in the
+ * distribution for a full listing of individual contributors.
+ *
+ * This is free software; you can redistribute it and/or modify it
+ * under the terms of the GNU Lesser General Public License as
+ * published by the Free Software Foundation; either version 2.1 of
+ * the License, or (at your option) any later version.
+ *
+ * This software is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+ * Lesser General Public License for more details.
+ *
+ * You should have received a copy of the GNU Lesser General Public
+ * License along with this software; if not, write to the Free
+ * Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
+ * 02110-1301 USA, or see the FSF site: http://www.fsf.org.
+ */
+package org.jboss.test.identity.federation.saml.v2;
+
+import java.util.List;
+
+import javax.xml.bind.JAXBElement;
+
+import junit.framework.TestCase;
+
+import org.jboss.identity.federation.saml.v2.assertion.AudienceRestrictionType;
+import org.jboss.identity.federation.saml.v2.assertion.ConditionAbstractType;
+import org.jboss.identity.federation.saml.v2.assertion.ConditionsType;
+import org.jboss.identity.federation.saml.v2.assertion.NameIDType;
+import org.jboss.identity.federation.saml.v2.assertion.SubjectType;
+import org.jboss.identity.federation.saml.v2.factories.JBossSAMLAuthnRequestFactory;
+import org.jboss.identity.federation.saml.v2.protocol.AuthnRequestType;
+import org.jboss.identity.federation.saml.v2.protocol.RequestedAuthnContextType;
+import org.jboss.identity.federation.w3.xmldsig.SignatureType;
+
+
+
+/**
+ * Unit test the SAML2 Authn Request Context constructs
+ * @author Anil.Saldhana(a)redhat.com
+ * @since Dec 8, 2008
+ */
+public class SAML2AuthnRequestUnitTestCase extends TestCase
+{
+ /**
+ * Test reading a saml2 authn request
+ * @throws Exception
+ */
+ public void testAuthnRequestExample() throws Exception
+ {
+ String resourceName = "saml/v2/authnrequest/samlAuthnRequestExample.xml";
+
+ AuthnRequestType authnRequestType = JBossSAMLAuthnRequestFactory.getAuthnRequestType(resourceName);
+
+ assertEquals("http://www.example.com/", authnRequestType.getDestination());
+ assertEquals("urn:oasis:names:tc:SAML:2.0:consent:obtained", authnRequestType.getConsent());
+ assertEquals("http://www.example.com/",authnRequestType.getAssertionConsumerServiceURL());
+ assertEquals(Integer.valueOf("0"), authnRequestType.getAttributeConsumingServiceIndex());
+
+ SubjectType subjectType = authnRequestType.getSubject();
+ assertNotNull(subjectType);
+
+ List<JAXBElement<?>> subjectContentList = subjectType.getContent();
+ JAXBElement<?> elem1 = subjectContentList.get(0);
+ NameIDType nameIDType = (NameIDType) elem1.getValue();
+
+ assertEquals("urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress",nameIDType.getFormat());
+ assertEquals("j.doe(a)company.com",nameIDType.getValue());
+
+ ConditionsType conditionsType = authnRequestType.getConditions();
+ List<ConditionAbstractType> conditions = conditionsType.getConditionOrAudienceRestrictionOrOneTimeUse();
+ assertTrue(conditions.size() == 1);
+
+ ConditionAbstractType condition = conditions.get(0);
+ assertTrue(condition instanceof AudienceRestrictionType);
+ AudienceRestrictionType audienceRestrictionType = (AudienceRestrictionType) condition;
+ List<String> audiences = audienceRestrictionType.getAudience();
+ assertTrue(audiences.size() == 1);
+ assertEquals("urn:foo:sp.example.org", audiences.get(0));
+
+ RequestedAuthnContextType requestedAuthnContext = authnRequestType.getRequestedAuthnContext();
+ assertEquals( "urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport"
+ ,requestedAuthnContext.getAuthnContextClassRef().get(0));
+ }
+
+ /**
+ * Test reading a saml authn request from a file that
+ * contains a digital signature
+ * @throws Exception
+ */
+ public void testAuthnRequestWithSignature() throws Exception
+ {
+ String resourceName = "saml/v2/authnrequest/samlAuthnRequestWithSignature.xml";
+
+ AuthnRequestType authnRequestType = JBossSAMLAuthnRequestFactory.getAuthnRequestType(resourceName);
+ assertNotNull(authnRequestType);
+
+ SignatureType signatureType = authnRequestType.getSignature();
+ assertNotNull("Signature is not null", signatureType);
+ }
+}
\ No newline at end of file
Property changes on: identity-federation/trunk/identity-opensaml/src/test/resources
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Property changes on: identity-federation/trunk/identity-opensaml/src/test/resources/endorsed
___________________________________________________________________
Name: svn:ignore
- target
+ target
target-eclipse .settings eclipse-target
Added: identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest/samlAuthnRequestExample.xml
===================================================================
(Binary files differ)
Property changes on: identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest/samlAuthnRequestExample.xml
___________________________________________________________________
Name: svn:mime-type
+ application/octet-stream
Added: identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest/samlAuthnRequestWithSignature.xml
===================================================================
--- identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest/samlAuthnRequestWithSignature.xml (rev 0)
+++ identity-federation/trunk/identity-opensaml/src/test/resources/saml/v2/authnrequest/samlAuthnRequestWithSignature.xml 2008-12-09 16:10:21 UTC (rev 127)
@@ -0,0 +1,68 @@
+<!-- Picked up from http://wiki.eclipse.org/SAML2_IdP_Overview -->
+<samlp:AuthnRequest
+ AssertionConsumerServiceURL="http://localhost/org.eclipse.higgins.saml2idp.test/SAMLEndpoint"
+ Destination="http://localhost/org.eclipse.higgins.saml2idp.server/SAMLEndpoint"
+ ID="a2sffdlgdhgfg32fdldsdghdsgdgfdglgx"
+ IssueInstant="2007-12-17T18:40:52.203Z"
+ ProtocolBinding="urn:oasis:names.tc:SAML:2.0:bindings:HTTP-Redirect"
+ ProviderName="Test SAML2 SP" Version="2.0"
+ xmlns="urn:oasis:names:tc:SAML:2.0:assertion"
+ xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
+ xmlns:xenc="http://www.w3.org/2001/04/xmlenc#">
+
+ <Issuer>Test SAML2 SP</Issuer>
+
+ <Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
+ <SignedInfo>
+ <CanonicalizationMethod
+ Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments" />
+ <SignatureMethod
+ Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1" />
+ <Reference URI="#ccocfkmlnocbajegpiheahonbcambbapiibggije">
+ <Transforms>
+ <Transform
+ Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
+ </Transforms>
+ <DigestMethod
+ Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" />
+ <DigestValue>N1Aze93QqDxax3cmBgPmKFNdM8U=</DigestValue>
+ </Reference>
+ </SignedInfo>
+ <SignatureValue>
+ KjfZwX9RkNrr3Epo/yRfDiFhqBeJCO5lFe/Ni/leBvBH8FRCT3p+2w==
+ </SignatureValue>
+ <KeyInfo>
+ <KeyValue>
+ <DSAKeyValue>
+ <P>
+ vzIPsacspz2XUcXP0hmWx2u56y9t/nTZRKGyFcVi1K/bao0C+0KjvXKkAPNhBb9TzYsCZbtZNH3a
+ OSVvsw1XVYHCeneHAircY/oJ0BqfBBg4gQe1H/CPXwixI+zjBSF5pMOBq4etcsH+SD/JYj1NsRwn
+ /2yQccUjUKeapbHn8TVNwVRYwg5QZL9AQ4b/pGoqO+df3kIqUL7lVyW+l6XprtVQU9jen47c4KQ1
+ sodHHPwgoXmT27hLAedC0cu4UUYFjwgbEoS1UBUoNajmGFNFeMpEtj1j4cHRoiZIxwYgEqzanp2f
+ Lgq7LlMa07vIuZBk6jyrw77Mza7TqxFNoVO89w==
+ </P>
+ <Q>j/ukaZe37ncVwe4c/+GQex1Kqic=</Q>
+ <G>
+ fu8RMe0ijgLi4Pw/KY57HdIBjmBge4XG1fX8IoT2wxv4QFO+FmijCqCcOiWk3osVyJIjqGJyH4kq
+ RwvSZl6pd8FAdP1HfZDMwBP9ML6NpE5WAe+MP+b3ydoUqI25JqCS2H9DypUIHxqN+NaLTDm67O9m
+ tTSckEMbXiARccwgnEgyNCFFulmm8vh8L6iT+56pesCyykMp6PDDo8AI2U9SR5EzUAQe5Yl39fCp
+ lb7H+tbOBclal00OUXezRGNh5c6JlM5J6YpY/gll2D0nv3VtubVOlc104LIpvFzphF7x5hv5HvI+
+ jUemrFIx0I8C3lv+8Xndwe8YwszLRrxvNe0jPQ==
+ </G>
+ <Y>
+ vM9EhHB8cKakhExdDZ/1pnWFeZOBKgC/c1/OoY1wGh4yAz5zDkkZPg/dXpEOkWuz241WXipcUbym
+ L+lZXcT+bTs8CQdIkw738vopoJfT0r75fKd85lT1pRH/nQ4i82J+vHrqOrfFc5CryxxqCRkZP4DW
+ B5t62LBoIMMsrdsMVKpzCJmUgnnIY8B4maJe2BYVRBBhISGoBnTKSWxObUg30fIfRlVFFxtTeWq8
+ tPS9u+MI3HuFn0MPVL+TgBw24ufSWPEEUiZU0eDdjzF51/yTVqUCHYNJH7gG7kugrQ8LdKes7rfD
+ c9glkilm1iAcSCfNvqsktKcN+BCOaCdsQhT5yw==
+ </Y>
+ </DSAKeyValue>
+ </KeyValue>
+ </KeyInfo>
+ </Signature>
+
+ <samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
+ AllowCreate="true"
+ />
+
+</samlp:AuthnRequest>
\ No newline at end of file
17 years, 7 months
JBoss Identity SVN: r125 - in trunk/identity-impl/src: main/java/org/jboss/identity/impl/store and 4 other directories.
by jboss-identity-commits@lists.jboss.org
Author: bdaw
Date: 2008-12-04 04:52:41 -0500 (Thu, 04 Dec 2008)
New Revision: 125
Modified:
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/JAXB2IdentityConfiguration.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/FeaturesMetaDataImpl.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreImpl.java
trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreTestCase.java
trunk/identity-impl/src/test/resources/ldap/initial-empty-opends.ldif
trunk/identity-impl/src/test/resources/ldap/initial-opends.ldif
trunk/identity-impl/src/test/resources/store-test-config.xml
Log:
reenable LDAP store test cases
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/JAXB2IdentityConfiguration.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/JAXB2IdentityConfiguration.java 2008-12-02 18:51:34 UTC (rev 124)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/JAXB2IdentityConfiguration.java 2008-12-04 09:52:41 UTC (rev 125)
@@ -31,8 +31,10 @@
import org.jboss.identity.impl.configuration.metadata.IdentityRepositoryConfigurationMetaDataImpl;
import org.jboss.identity.impl.configuration.metadata.IdentityStoreConfigurationMetaDataImpl;
import org.jboss.identity.impl.configuration.metadata.IdentityStoreMappingMetaDataImpl;
+import org.jboss.identity.impl.configuration.metadata.RelationshipMetaDataImpl;
import org.jboss.identity.spi.configuration.metadata.IdentityStoreMappingMetaData;
import org.jboss.identity.spi.configuration.metadata.IdentityConfigurationMetaData;
+import org.jboss.identity.spi.configuration.metadata.RelationshipMetaData;
import org.jboss.identity.spi.exception.IdentityConfigurationException;
import org.jboss.identity.spi.attribute.AttributeMetaData;
import org.jboss.identity.spi.attribute.AttributeMetaDataImpl;
@@ -46,6 +48,7 @@
import org.jboss.identity.impl.configuration.jaxb2.generated.IdentityStoreMappingType;
import org.jboss.identity.impl.configuration.jaxb2.generated.IdentityObjectTypeType;
import org.jboss.identity.impl.configuration.jaxb2.generated.AttributeType;
+import org.jboss.identity.impl.configuration.jaxb2.generated.RelationshipType;
import javax.xml.bind.JAXBContext;
import javax.xml.bind.Unmarshaller;
@@ -223,6 +226,9 @@
identityObjectTypeMD.setName(identityObjectTypeType.getName());
+
+ // Attributes
+
List<AttributeMetaData> attributes = new LinkedList<AttributeMetaData>();
if (identityObjectTypeType.getAttributes() != null &&
@@ -260,6 +266,8 @@
identityObjectTypeMD.setAttributes(attributes);
+ // Credentials
+
List<String> credentials = new LinkedList<String>();
if (identityObjectTypeType.getCredentials() != null &&
@@ -273,6 +281,26 @@
identityObjectTypeMD.setCredentials(credentials);
+ // Relationships
+
+ List<RelationshipMetaData> relationships = new LinkedList<RelationshipMetaData>();
+
+ if (identityObjectTypeType.getRelationships() != null &&
+ identityObjectTypeType.getRelationships().getRelationship() != null)
+ {
+ for (RelationshipType relationshipType : identityObjectTypeType.getRelationships().getRelationship())
+ {
+ RelationshipMetaDataImpl relMD = new RelationshipMetaDataImpl();
+ relMD.setIdentityObjectTypeRef(relationshipType.getIdentityObjectTypeRef());
+ relMD.setRelationshipTypeRef(relationshipType.getRelationshipTypeRef());
+ relationships.add(relMD);
+ }
+ }
+
+ identityObjectTypeMD.setRelationships(relationships);
+
+ // Options
+
Map<String, List<String>> options = new HashMap<String, List<String>>();
if (identityObjectTypeType.getOptions() != null &&
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/FeaturesMetaDataImpl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/FeaturesMetaDataImpl.java 2008-12-02 18:51:34 UTC (rev 124)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/FeaturesMetaDataImpl.java 2008-12-04 09:52:41 UTC (rev 125)
@@ -52,7 +52,8 @@
private final Map<String, Set<String>> supportedCredentials;
- private Map<String, Map<String, Set<String>>> supportedRelationshipMappings = new HashMap<String, Map<String, Set<String>>>();
+ // <Relationship Type, <From IdentityType, To IdentityType>>
+ private final Map<String, Map<String, Set<String>>> supportedRelationshipMappings = new HashMap<String, Map<String, Set<String>>>();
public FeaturesMetaDataImpl(IdentityStoreConfigurationMetaData configurationMD,
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreImpl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreImpl.java 2008-12-02 18:51:34 UTC (rev 124)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreImpl.java 2008-12-04 09:52:41 UTC (rev 125)
@@ -106,6 +106,11 @@
public void bootstrap(IdentityStoreConfigurationMetaData configurationMD) throws IdentityException
{
+ if (configurationMD == null)
+ {
+ throw new IllegalArgumentException("Configuration is null");
+ }
+
configuration = new SimpleLDAPIdentityStoreConfiguration(configurationMD);
supportedFeatures = new FeaturesMetaDataImpl(configurationMD, supportedSearchControls);
@@ -305,7 +310,12 @@
}
//log.debug("Search filter: " + filter);
- List sr = searchIdentityObjects(ctx, identityType, filter, null, new String[]{getTypeConfiguration(ctx, identityType).getIdAttributeName()});
+ List sr = searchIdentityObjects(ctx,
+ identityType,
+ filter,
+ null,
+ new String[]{getTypeConfiguration(ctx, identityType).getIdAttributeName()},
+ null);
return sr.size();
@@ -346,13 +356,23 @@
if (filter != null && filter.length() > 0)
{
Object[] filterArgs = {name};
- sr = searchIdentityObjects(invocationCtx, type, filter, filterArgs, new String[]{getTypeConfiguration(invocationCtx, type).getIdAttributeName()});
+ sr = searchIdentityObjects(invocationCtx,
+ type,
+ filter,
+ filterArgs,
+ new String[]{getTypeConfiguration(invocationCtx, type).getIdAttributeName()},
+ null);
}
else
{
//search all entries
filter = "(".concat(getTypeConfiguration(invocationCtx, type).getIdAttributeName()).concat("=").concat(name).concat(")");
- sr = searchIdentityObjects(invocationCtx, type, filter, null, new String[]{getTypeConfiguration(invocationCtx, type).getIdAttributeName()});
+ sr = searchIdentityObjects(invocationCtx,
+ type,
+ filter,
+ null,
+ new String[]{getTypeConfiguration(invocationCtx, type).getIdAttributeName()},
+ null);
}
//log.debug("Search filter: " + filter);
@@ -539,19 +559,21 @@
checkIOType(type);
- List<IdentityObject> objects = new LinkedList<IdentityObject>();
+ LinkedList<IdentityObject> objects = new LinkedList<IdentityObject>();
LDAPIdentityObjectTypeConfiguration typeConfiguration = getTypeConfiguration(invocationCtx, type);
try
{
+ Control[] requestControls = null;
+
// Sort control
if (sortSearchControl != null)
{
//TODO: make criticallity optional
- ctx.setRequestControls(new Control[]{
+ requestControls = new Control[]{
new SortControl(typeConfiguration.getIdAttributeName(), Control.NONCRITICAL)
- });
+ };
}
StringBuilder af = new StringBuilder();
@@ -583,12 +605,22 @@
{
Object[] filterArgs = {nameFilter};
- sr = searchIdentityObjects(invocationCtx, type, "&(" + filter + ")" + af.toString(), filterArgs, new String[]{typeConfiguration.getIdAttributeName()});
+ sr = searchIdentityObjects(invocationCtx,
+ type,
+ "(&(" + filter + ")" + af.toString() + ")",
+ filterArgs,
+ new String[]{typeConfiguration.getIdAttributeName()},
+ requestControls);
}
else
{
filter = "(".concat(typeConfiguration.getIdAttributeName()).concat("=").concat(nameFilter).concat(")");
- sr = searchIdentityObjects(invocationCtx, type, "&(" + filter + ")" + af.toString(), null, new String[]{typeConfiguration.getIdAttributeName()});
+ sr = searchIdentityObjects(invocationCtx,
+ type,
+ "(&(" + filter + ")" + af.toString() + ")",
+ null,
+ new String[]{typeConfiguration.getIdAttributeName()},
+ requestControls);
}
@@ -596,18 +628,26 @@
{
ctx = (LdapContext)res.getObject();
String dn = ctx.getNameInNamespace();
- objects.add(createIdentityObjectInstance(invocationCtx, type, res.getAttributes(), dn));
+ if (sortSearchControl != null)
+ {
+ //TODO: It seams that sort control returns entries in descending order by default...
+ if (!sortSearchControl.isAscending())
+ {
+ objects.addFirst(createIdentityObjectInstance(invocationCtx, type, res.getAttributes(), dn));
+ }
+ else
+ {
+ objects.addLast(createIdentityObjectInstance(invocationCtx, type, res.getAttributes(), dn));
+ }
+ }
+ else
+ {
+ objects.add(createIdentityObjectInstance(invocationCtx, type, res.getAttributes(), dn));
+ }
}
ctx.close();
- // Post sort if the order was descending
- if (sortSearchControl != null && !sortSearchControl.isAscending());
- {
- //TODO: rather sucks for the performance but I don't see how to do this with JNDI SortControl
- //TODO: check if result was sorted (if the control was NONCRITICAL) to save some cycles
- Collections.reverse(objects);
- }
return objects;
}
@@ -642,101 +682,6 @@
return findIdentityObject(invocationCtx, type, null);
}
-// public Collection<IdentityObject> findIdentityObject(IdentityStoreInvocationContext invocationCtx, IdentityObjectType type, Map<String, String[]> attributes, int offset, int limit, boolean orderByName, boolean ascending) throws IdentityException
-// {
-// //TODO: handle paged results and sort
-//
-// if (log.isLoggable(Level.FINER))
-// {
-// log.finer(toString() + ".findIdentityObject with type: " + type
-// + "; attributes: " + attributes
-// + "; offset: " + offset
-// + "; limit: " + limit
-// + "; orderByName: " + orderByName
-// + "; ascending: " + ascending
-// );
-// }
-//
-// Context ctx = getLDAPContext(invocationCtx);
-// checkIOType(type);
-//
-// List<IdentityObject> objects = new LinkedList<IdentityObject>();
-//
-// try
-// {
-// String filter = getTypeConfiguration(invocationCtx, type).getEntrySearchFilter();
-// List<SearchResult> sr = null;
-//
-// //TODO: if no search filter is present just use search method with matchingAttributes from DirContext instead of
-// //TODO: concatenating filter
-//
-// StringBuilder af = new StringBuilder("(&");
-//
-// for (Map.Entry<String, String[]> stringEntry : attributes.entrySet())
-// {
-// for (String value : stringEntry.getValue())
-// {
-// af.append("(")
-// .append(stringEntry.getKey())
-// .append("=")
-// .append(value)
-// .append(")");
-// }
-// }
-//
-// af.append(")");
-//
-// if (filter != null && filter.length() > 0)
-// {
-// // chars are escaped in filterArgs so we must replace it manually
-// filter = filter.replaceAll("\\{0\\}", "*");
-//
-// Object[] filterArgs = {};
-// sr = searchIdentityObjects(invocationCtx, type, "&(" + filter + ")" + af.toString(), filterArgs, new String[]{getTypeConfiguration(invocationCtx, type).getIdAttributeName()});
-// }
-// else
-// {
-// filter = "(".concat(getTypeConfiguration(invocationCtx, type).getIdAttributeName()).concat("=").concat("*").concat(")");
-// sr = searchIdentityObjects(invocationCtx, type, "&(" + filter + ")" + af.toString(), null, new String[]{getTypeConfiguration(invocationCtx, type).getIdAttributeName()});
-// }
-//
-//
-// for (SearchResult res : sr)
-// {
-// ctx = (Context)res.getObject();
-// String dn = ctx.getNameInNamespace();
-// objects.add(createIdentityObjectInstance(invocationCtx, type, res.getAttributes(), dn));
-// }
-//
-// ctx.close();
-// return objects;
-//
-// }
-// catch (NoSuchElementException e)
-// {
-// //log.debug("No identity object found with name: " + name, e);
-// }
-// catch (NamingException e)
-// {
-// throw new IdentityException("IdentityObject search failed.", e);
-// }
-// finally
-// {
-// try
-// {
-// if (ctx != null)
-// {
-// ctx.close();
-// }
-// }
-// catch (NamingException e)
-// {
-// throw new IdentityException("Failed to close LDAP connection", e);
-// }
-// }
-//
-// return objects;
-// }
public Collection<IdentityObject> findIdentityObject(IdentityStoreInvocationContext ctx, IdentityObject identity, IdentityObjectRelationshipType relationshipType, boolean parent, IdentityObjectSearchControl[] controls) throws IdentityException
{
@@ -956,9 +901,10 @@
LdapContext ldapContext = getLDAPContext(ctx);
// Check posibilities
- //TODO: Supported features should handle information from type configurations
- if (!getSupportedFeatures().isRelationshipTypeSupported(fromIdentity.getIdentityType(), toIdentity.getIdentityType(), relationshipType))
+ //TODO: null RelationshipType passed from removeRelationships
+ if (relationshipType != null &&
+ !getSupportedFeatures().isRelationshipTypeSupported(fromIdentity.getIdentityType(), toIdentity.getIdentityType(), relationshipType))
{
throw new IdentityException("Relationship not supported");
}
@@ -1117,12 +1063,6 @@
throw new OperationNotSupportedException("Named relationships are not supported by this implementation of LDAP IdentityStore");
}
- public boolean hasPasswordAttribute(IdentityStoreInvocationContext ctx, IdentityObjectType type) throws IdentityException
- {
- //TODO: NYI
- throw new NotYetImplementedException();
- }
-
public boolean validateCredential(IdentityStoreInvocationContext ctx, IdentityObject identityObject, IdentityObjectCredential credential) throws IdentityException
{
//TODO: NYI
@@ -1479,24 +1419,35 @@
return ldapio;
}
- public List<SearchResult> searchIdentityObjects(IdentityStoreInvocationContext ctx, IdentityObjectType type, String filter, Object[] filterArgs, String[] returningAttributes) throws NamingException, IdentityException
+ public List<SearchResult> searchIdentityObjects(IdentityStoreInvocationContext ctx,
+ IdentityObjectType type,
+ String filter,
+ Object[] filterArgs,
+ String[] returningAttributes,
+ Control[] requestControls) throws NamingException, IdentityException
{
LdapContext ldapContext = getLDAPContext(ctx);
+
+ if (ldapContext != null)
+ {
+ ldapContext.setRequestControls(requestControls);
+ }
+
NamingEnumeration results = null;
try
{
- SearchControls controls = new SearchControls();
- controls.setSearchScope(SearchControls.ONELEVEL_SCOPE);
- controls.setReturningObjFlag(true);
- controls.setTimeLimit(getConfiguration(ctx).getSearchTimeLimit());
+ SearchControls searchControls = new SearchControls();
+ searchControls.setSearchScope(SearchControls.ONELEVEL_SCOPE);
+ searchControls.setReturningObjFlag(true);
+ searchControls.setTimeLimit(getConfiguration(ctx).getSearchTimeLimit());
if (returningAttributes != null)
{
- controls.setReturningAttributes(returningAttributes);
+ searchControls.setReturningAttributes(returningAttributes);
}
@@ -1506,11 +1457,11 @@
{
if (filterArgs == null)
{
- results = ldapContext.search(entryCtxs[0], filter, controls);
+ results = ldapContext.search(entryCtxs[0], filter, searchControls);
}
else
{
- results = ldapContext.search(entryCtxs[0], filter, filterArgs, controls);
+ results = ldapContext.search(entryCtxs[0], filter, filterArgs, searchControls);
}
return Tools.toList(results);
@@ -1524,11 +1475,11 @@
{
if (filterArgs == null)
{
- results = ldapContext.search(entryCtx, filter, controls);
+ results = ldapContext.search(entryCtx, filter, searchControls);
}
else
{
- results = ldapContext.search(entryCtx, filter, filterArgs, controls);
+ results = ldapContext.search(entryCtx, filter, filterArgs, searchControls);
}
merged.addAll(Tools.toList(results));
results.close();
Modified: trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreTestCase.java
===================================================================
--- trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreTestCase.java 2008-12-02 18:51:34 UTC (rev 124)
+++ trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreTestCase.java 2008-12-04 09:52:41 UTC (rev 125)
@@ -1,514 +1,510 @@
-///*
-//* JBoss, a division of Red Hat
-//* Copyright 2006, Red Hat Middleware, LLC, and individual contributors as indicated
-//* by the @authors tag. See the copyright.txt in the distribution for a
-//* full listing of individual contributors.
-//*
-//* This is free software; you can redistribute it and/or modify it
-//* under the terms of the GNU Lesser General Public License as
-//* published by the Free Software Foundation; either version 2.1 of
-//* the License, or (at your option) any later version.
-//*
-//* This software is distributed in the hope that it will be useful,
-//* but WITHOUT ANY WARRANTY; without even the implied warranty of
-//* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
-//* Lesser General Public License for more details.
-//*
-//* You should have received a copy of the GNU Lesser General Public
-//* License along with this software; if not, write to the Free
-//* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
-//* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
-//*/
-//
-//package org.jboss.identity.impl.store.ldap;
-//
-//import junit.framework.TestCase;
-//import org.jboss.identity.opends.OpenDSService;
-//import org.jboss.identity.spi.store.IdentityStore;
-//import org.jboss.identity.spi.store.IdentityStoreInvocationContext;
-//import org.jboss.identity.spi.model.IdentityObject;
-//import org.jboss.identity.impl.store.IdentityTypeEnum;
-//import org.jboss.identity.impl.store.CommonIdentityStoreTest;
-//import org.jboss.identity.impl.store.IdentityStoreTestContext;
-//import org.opends.server.tools.LDAPModify;
-//
-//import javax.naming.Context;
-//import javax.naming.NamingException;
-//import javax.naming.NamingEnumeration;
-//import javax.naming.Binding;
-//import javax.naming.directory.DirContext;
-//import javax.naming.ldap.LdapContext;
-//import javax.naming.ldap.InitialLdapContext;
-//import java.net.URL;
-//import java.util.Hashtable;
-//import java.util.Map;
-//import java.util.HashMap;
-//import java.util.Set;
-//import java.util.HashSet;
-//import java.util.logging.Logger;
-//import java.util.logging.Level;
-//import java.io.File;
-//
-///**
-// * @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
-// * @version : 0.1 $
-// */
-//public class LDAPIdentityStoreTestCase extends TestCase implements IdentityStoreTestContext
-//{
-//
-// public static final String LDAP_HOST = "localhost";
-//
-// public static final String LDAP_PORT = "10389";
-//
-// public static final String LDAP_PROVIDER_URL = "ldap://" + LDAP_HOST + ":" + LDAP_PORT;
-//
-// public static final String LDAP_PRINCIPAL = "cn=Directory Manager";
-//
-// public static final String LDAP_CREDENTIALS = "password";
-//
-// OpenDSService openDSService = new OpenDSService("target/test-classes/opends");
-//
-// IdentityStore store;
-//
-// CommonIdentityStoreTest commonTest;
-//
-// LDAPIdentityStoreInvocationContext ctx;
-//
-// public LDAPIdentityStoreTestCase(String s)
-// {
-// super(s);
-// commonTest = new CommonIdentityStoreTest(this);
-// }
-//
-// protected void setUp() throws Exception
-// {
-// super.setUp();
-//
-// openDSService.start();
-//
-// // Initiate invocation context with simple configuration
-// initiateCtx();
-//
-//// populate();
-//
-// store = new LDAPIdentityStore("simpleTestLDAPStore");
-//
-//
-//
-// }
-//
-// protected void tearDown() throws Exception
-// {
-// super.tearDown();
-//
-// cleanUp();
-//
-// openDSService.stop();
-// }
-//
-// public void begin() throws Exception
-// {
-// //nothing
-// }
-//
-// public void commit() throws Exception
-// {
-// //nothing
-// }
-//
-// public void flush() throws Exception
-// {
-// //nothing
-// }
-//
-// public IdentityStore getStore()
-// {
-// return store;
-// }
-//
-// public IdentityStoreInvocationContext getCtx()
-// {
-// return ctx;
-// }
-//
-//
-//
-//
-//
-// public void populate() throws Exception
-// {
-// populateLDIF("target/test-classes/ldap/initial-opends.ldif");
-// }
-//
-// public void populateClean() throws Exception
-// {
-// populateLDIF("target/test-classes/ldap/initial-empty-opends.ldif");
-// }
-//
-// public void populateLDIF(String ldifRelativePath) throws Exception
-// {
-// File ldif = new File(ldifRelativePath);
-//
-// System.out.println("LDIF: " + ldif.getAbsolutePath());
-//
-// String[] cmd = new String[] {"-h", LDAP_HOST,
-// "-p", LDAP_PORT,
-// "-D", LDAP_PRINCIPAL,
-// "-w", LDAP_CREDENTIALS,
-// "-a", "-f", ldif.getPath()};
-//
-// System.out.println("Populate success: " + (LDAPModify.mainModify(cmd, false, System.out, System.err) == 0));
-//
-// }
-//
-// protected void cleanUp() throws Exception
-// {
-// try
-// {
-//
-// DirContext ldapCtx = ctx.getLdapContext();
-// String dn = "dc=portal,dc=example,dc=com";
-//
-// System.out.println("Removing: " + dn);
-//
-// removeContext(ldapCtx, dn);
-// }
-// catch (Exception e)
-// {
-// //
-// }
-// }
-//
-// //subsequent remove of javax.naming.Context
-// protected void removeContext(Context mainCtx, String name) throws Exception
-// {
-// Context deleteCtx = (Context)mainCtx.lookup(name);
-// NamingEnumeration subDirs = mainCtx.listBindings(name);
-//
-// while (subDirs.hasMoreElements())
-// {
-// Binding binding = (Binding)subDirs.nextElement();
-// String subName = binding.getName();
-//
-// removeContext(deleteCtx, subName);
-// }
-//
-// mainCtx.unbind(name);
-// }
-//
-// private void initiateCtx()
-// {
-//
-// Map<String, LDAPIdentityObjectTypeConfiguration> typesMap = new HashMap<String, LDAPIdentityObjectTypeConfiguration>();
-//
-// //USER
-// SimpleLDAPIdentityObjectTypeConfiguration tc = new SimpleLDAPIdentityObjectTypeConfiguration();
-// tc.setAllowCreateEntry(true);
-// tc.setAllowedMembershipTypes(new String[] {});
-// tc.setAllowEmptyMemberships(true);
-// Map<String, String> attrs = new HashMap<String, String>();
-// attrs.put("phone", "telephoneNumber");
-// attrs.put("description", "description");
-// attrs.put("carLicense", "carLicense");
-// tc.setAttributeNames(attrs);
-// Map<String, String[]> newAttrs = new HashMap<String, String[]>();
-// newAttrs.put("objectClass", new String[]{"top", "inetOrgPerson"});
-// newAttrs.put("sn", new String[]{" "});
-// newAttrs.put("cn", new String[]{" "});
-//
-// tc.setCreateEntryAttributeValues(newAttrs);
-// tc.setCtxDNs(new String[] {"ou=People,o=test,dc=portal,dc=example,dc=com"});
-// tc.setEntrySearchFilter(null);
-// tc.setIdAttributeName("uid");
-// tc.setMembershipAttributeDN(true);
-// tc.setMembershipAttributeName(null);
-// typesMap.put(IdentityTypeEnum.USER.getName(), tc);
-//
-//
-// // ROLE
-// tc = new SimpleLDAPIdentityObjectTypeConfiguration();
-// tc.setAllowCreateEntry(true);
-// tc.setAllowedMembershipTypes(new String[] {IdentityTypeEnum.USER.getName()});
-// tc.setAllowEmptyMemberships(true);
-// attrs = new HashMap<String, String>();
-// //attrs.put();
-// tc.setAttributeNames(attrs);
-// newAttrs = new HashMap<String, String[]>();
-// newAttrs.put("objectClass", new String[]{"top", "groupOfNames"});
-// tc.setCreateEntryAttributeValues(newAttrs);
-// tc.setCtxDNs(new String[] {"ou=Roles,o=test,dc=portal,dc=example,dc=com"});
-// tc.setEntrySearchFilter(null);
-// tc.setIdAttributeName("cn");
-// tc.setMembershipAttributeDN(true);
-// tc.setMembershipAttributeName("member");
-// typesMap.put(IdentityTypeEnum.ROLE.getName(), tc);
-//
-// // GROUP
-// tc = new SimpleLDAPIdentityObjectTypeConfiguration();
-// tc.setAllowCreateEntry(true);
-// tc.setAllowedMembershipTypes(new String[] {IdentityTypeEnum.USER.getName(), IdentityTypeEnum.ROLE.getName(), IdentityTypeEnum.GROUP.getName()});
-// tc.setAllowEmptyMemberships(true);
-// attrs = new HashMap<String, String>();
-// //attrs.put();
-// tc.setAttributeNames(attrs);
-// newAttrs = new HashMap<String, String[]>();
-// newAttrs.put("objectClass", new String[]{"top", "groupOfNames"});
-//
-// tc.setCreateEntryAttributeValues(newAttrs);
-// tc.setCtxDNs(new String[] {"ou=Groups,o=test,dc=portal,dc=example,dc=com"});
-// tc.setEntrySearchFilter(null);
-// tc.setIdAttributeName("cn");
-// tc.setMembershipAttributeDN(true);
-// tc.setMembershipAttributeName("member");
-// typesMap.put(IdentityTypeEnum.GROUP.getName(), tc);
-//
-// // ORGANIZATION
-// tc = new SimpleLDAPIdentityObjectTypeConfiguration();
-// tc.setAllowCreateEntry(true);
-// tc.setAllowedMembershipTypes(new String[] {IdentityTypeEnum.USER.getName(), IdentityTypeEnum.ROLE.getName(), IdentityTypeEnum.GROUP.getName()});
-// tc.setAllowEmptyMemberships(true);
-// attrs = new HashMap<String, String>();
-// //attrs.put();
-// tc.setAttributeNames(attrs);
-// newAttrs = new HashMap<String, String[]>();
-// newAttrs.put("objectClass", new String[]{"top", "groupOfNames"});
-//
-// tc.setCreateEntryAttributeValues(newAttrs);
-// tc.setCtxDNs(new String[] {"ou=Organizations,o=test,dc=portal,dc=example,dc=com"});
-// tc.setEntrySearchFilter(null);
-// tc.setIdAttributeName("cn");
-// tc.setMembershipAttributeDN(true);
-// tc.setMembershipAttributeName("member");
-// typesMap.put(IdentityTypeEnum.ORGANIZATION.getName(), tc);
-//
-//
-// SimpleLDAPIdentityStoreConfiguration configuration =
-// new SimpleLDAPIdentityStoreConfiguration(
-// LDAP_PROVIDER_URL,
-// LDAP_PRINCIPAL,
-// LDAP_CREDENTIALS,
-// 10000,
-// typesMap);
-//
-// ctx = new SimpleLDAPIdentityStoreInvocationContext(configuration);
-// }
-//
-//
-// // Tests
-//
-//// Just test if OpenDS is running and was populated...
-// public void testSimple() throws Exception
-// {
-// populate();
-//
-// Hashtable<String,String> env = new Hashtable<String,String>();
-// env.put(Context.INITIAL_CONTEXT_FACTORY, "com.sun.jndi.ldap.LdapCtxFactory");
-// env.put(Context.PROVIDER_URL, LDAP_PROVIDER_URL);
-// env.put(Context.SECURITY_AUTHENTICATION, "simple");
-// env.put(Context.SECURITY_PRINCIPAL, LDAP_PRINCIPAL);
-// env.put(Context.SECURITY_CREDENTIALS, LDAP_CREDENTIALS);
-//
-// LdapContext ldapCtx = null;
-// try
-// {
-// ldapCtx = new InitialLdapContext(env, null);
-//
-//// Do something ...
-// System.out.println("Attributes: " + ldapCtx.getAttributes("o=test,dc=portal,dc=example,dc=com"));
-//
-// }
-// catch (NamingException e)
-// {
-// e.printStackTrace();
-// }
-// finally
-// {
-// try
-// {
-// if (ldapCtx != null)
-// {
-// ldapCtx.close();
-// }
-// }
-// catch (NamingException e)
-// {
-// e.printStackTrace();
-// }
-// }
-// }
-//
-// public void testIdentityObjectCount() throws Exception
-// {
-// populate();
-//
-// assertEquals(7, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.USER));
-// assertEquals(5, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.ROLE));
-// assertEquals(2, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.GROUP));
-// }
-//
-// public void testFindCreateRemove() throws Exception
-// {
-// populate();
-//
-// assertEquals(7, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.USER));
-//
-// IdentityObject io = store.findIdentityObject(ctx, "admin", IdentityTypeEnum.USER);
-// assertEquals("admin", io.getName());
-// assertEquals("uid=admin,ou=People,o=test,dc=portal,dc=example,dc=com", io.getId().toString());
-//
-// //
-//
-// store.removeIdentityObject(ctx, io);
-//
-// assertEquals(6, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.USER));
-//
-// store.createIdentityObject(ctx, "newUserA", IdentityTypeEnum.USER);
-//
-// assertEquals(7, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.USER));
-//
-// //
-//
-// assertEquals(2, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.GROUP));
-//
-// store.createIdentityObject(ctx, "newGroupA", IdentityTypeEnum.GROUP);
-//
-// assertEquals(3, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.GROUP));
-//
-// //
-//
-// io = store.findIdentityObject(ctx, "cn=newGroupA,ou=Groups,o=test,dc=portal,dc=example,dc=com");
-// assertEquals("newGroupA", io.getName());
-//
-// }
-//
-// public void testAttributes() throws Exception{
-//
-// populate();
-//
-// IdentityObject user1 = store.createIdentityObject(ctx, "Adam", IdentityTypeEnum.USER);
-// IdentityObject user2 = store.createIdentityObject(ctx, "Eva", IdentityTypeEnum.USER);
-//
-// //
-//
-// Map<String, Set<String>> attrs = new HashMap<String, Set<String>>();
-// HashSet<String> vals = new HashSet<String>();
-// vals.add("val1");
-// vals.add("val2");
-// vals.add("val3");
-//
-// attrs.put("phone", vals);
-//
-// vals = new HashSet<String>();
-// vals.add("val1");
-// vals.add("val2");
-// vals.add("val3");
-// vals.add("val4");
-// attrs.put("description", vals);
-//
-// store.addAttributes(ctx, user1, attrs);
-//
-// //
-//
-// Map<String, Set<String>> persistedAttrs = store.getAttributes(ctx, user1);
-//
-// assertEquals(2, persistedAttrs.keySet().size());
-//
-// assertTrue(persistedAttrs.containsKey("phone"));
-// assertEquals(3, persistedAttrs.get("phone").size());
-//
-// assertTrue(persistedAttrs.containsKey("description"));
-// assertEquals(4, persistedAttrs.get("description").size());
-//
-// //
-//
-// attrs = new HashMap<String, Set<String>>();
-// vals = new HashSet<String>();
-// vals.add("val1");
-// attrs.put("carLicense", vals);
-//
-// store.addAttributes(ctx, user1, attrs);
-//
-// //
-//
-// persistedAttrs = store.getAttributes(ctx, user1);
-//
-// assertEquals(3, persistedAttrs.keySet().size());
-//
-// assertTrue(persistedAttrs.containsKey("phone"));
-// assertEquals(3, persistedAttrs.get("phone").size());
-//
-// assertTrue(persistedAttrs.containsKey("description"));
-// assertEquals(4, persistedAttrs.get("description").size());
-//
-// assertTrue(persistedAttrs.containsKey("carLicense"));
-// assertEquals(1, persistedAttrs.get("carLicense").size());
-//
-// //
-//
-// vals = new HashSet<String>();
-// vals.add("val2");
-// attrs.put("carLicense", vals);
-//
-// store.addAttributes(ctx, user1, attrs);
-//
-// //
-//
-// persistedAttrs = store.getAttributes(ctx, user1);
-//
-// assertEquals(3, persistedAttrs.keySet().size());
-//
-// assertTrue(persistedAttrs.containsKey("carLicense"));
-// assertEquals(2, persistedAttrs.get("carLicense").size());
-//
-// //
-//
-// store.updateAttributes(ctx, user1, attrs);
-//
-// //
-//
-// persistedAttrs = store.getAttributes(ctx, user1);
-//
-// assertEquals(3, persistedAttrs.keySet().size());
-//
-// assertTrue(persistedAttrs.containsKey("carLicense"));
-// assertEquals(1, persistedAttrs.get("carLicense").size());
-//
-// //
-//
-// Set<String> names = new HashSet<String>();
-// names.add("carLicense");
-// store.removeAttributes(ctx, user1, names);
-//
-// //
-//
-// persistedAttrs = store.getAttributes(ctx, user1);
-//
-// assertEquals(2, persistedAttrs.keySet().size());
-//
-// }
-//
-// public void testRelationships() throws Exception
-// {
-// populateClean();
-//
-// commonTest.testRelationships();
-//
-// }
-//
-// public void testStorePersistence() throws Exception
-// {
-// populateClean();
-//
-// commonTest.testStorePersistence();
-//
-// }
-//
-// public void testFindMethods() throws Exception
-// {
-// populateClean();
-//
-// commonTest.testFindMethods();
-//
-// }
-//
-//}
+/*
+* JBoss, a division of Red Hat
+* Copyright 2006, Red Hat Middleware, LLC, and individual contributors as indicated
+* by the @authors tag. See the copyright.txt in the distribution for a
+* full listing of individual contributors.
+*
+* This is free software; you can redistribute it and/or modify it
+* under the terms of the GNU Lesser General Public License as
+* published by the Free Software Foundation; either version 2.1 of
+* the License, or (at your option) any later version.
+*
+* This software is distributed in the hope that it will be useful,
+* but WITHOUT ANY WARRANTY; without even the implied warranty of
+* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+* Lesser General Public License for more details.
+*
+* You should have received a copy of the GNU Lesser General Public
+* License along with this software; if not, write to the Free
+* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
+* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
+*/
+
+package org.jboss.identity.impl.store.ldap;
+
+import junit.framework.TestCase;
+import org.jboss.identity.opends.OpenDSService;
+import org.jboss.identity.spi.store.IdentityStore;
+import org.jboss.identity.spi.store.IdentityStoreInvocationContext;
+import org.jboss.identity.spi.store.IdentityStoreSession;
+import org.jboss.identity.spi.model.IdentityObject;
+import org.jboss.identity.spi.configuration.metadata.IdentityConfigurationMetaData;
+import org.jboss.identity.spi.configuration.metadata.IdentityStoreConfigurationMetaData;
+import org.jboss.identity.impl.store.IdentityTypeEnum;
+import org.jboss.identity.impl.store.CommonIdentityStoreTest;
+import org.jboss.identity.impl.store.IdentityStoreTestContext;
+import org.jboss.identity.impl.configuration.jaxb2.JAXB2IdentityConfiguration;
+import org.jboss.identity.exception.IdentityException;
+import org.opends.server.tools.LDAPModify;
+
+import javax.naming.Context;
+import javax.naming.NamingException;
+import javax.naming.NamingEnumeration;
+import javax.naming.Binding;
+import javax.naming.directory.DirContext;
+import javax.naming.ldap.LdapContext;
+import javax.naming.ldap.InitialLdapContext;
+import java.net.URL;
+import java.util.Hashtable;
+import java.util.Map;
+import java.util.HashMap;
+import java.util.Set;
+import java.util.HashSet;
+import java.util.logging.Logger;
+import java.util.logging.Level;
+import java.io.File;
+
+/**
+ * @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
+ * @version : 0.1 $
+ */
+public class LDAPIdentityStoreTestCase extends TestCase implements IdentityStoreTestContext
+{
+
+ public static final String LDAP_HOST = "localhost";
+
+ public static final String LDAP_PORT = "10389";
+
+ public static final String LDAP_PROVIDER_URL = "ldap://" + LDAP_HOST + ":" + LDAP_PORT;
+
+ public static final String LDAP_PRINCIPAL = "cn=Directory Manager";
+
+ public static final String LDAP_CREDENTIALS = "password";
+
+ OpenDSService openDSService = new OpenDSService("target/test-classes/opends");
+
+ IdentityStore store;
+
+ CommonIdentityStoreTest commonTest;
+
+ IdentityStoreInvocationContext ctx;
+
+ public LDAPIdentityStoreTestCase(String s)
+ {
+ super(s);
+ commonTest = new CommonIdentityStoreTest(this);
+ }
+
+ protected void setUp() throws Exception
+ {
+ super.setUp();
+
+ openDSService.start();
+
+ IdentityConfigurationMetaData configurationMD = JAXB2IdentityConfiguration
+ .createConfigurationMetaData(new File("src/test/resources/store-test-config.xml"));
+
+ IdentityStoreConfigurationMetaData storeMD = null;
+
+ for (IdentityStoreConfigurationMetaData metaData : configurationMD.getIdentityStores())
+ {
+ if (metaData.getId().equals("LDAPTestStore"))
+ {
+ storeMD = metaData;
+ break;
+ }
+ }
+
+ ctx = new IdentityStoreInvocationContext()
+ {
+ public IdentityStoreSession getIdentityStoreSession()
+ {
+ return new IdentityStoreSession(){
+
+ public Object getSessionContext() throws IdentityException
+ {
+ try
+ {
+ return getLdapContext();
+ }
+ catch (Exception e)
+ {
+ throw new IdentityException("Failed to obtain LDAP connection: ", e);
+ }
+ }
+
+ public void close() throws IdentityException
+ {
+
+ }
+
+ public void save() throws IdentityException
+ {
+
+ }
+
+ public void clear() throws IdentityException
+ {
+
+ }
+
+ public boolean isOpen()
+ {
+ return false;
+ }
+
+ public boolean isTransactionSupported()
+ {
+ return false;
+ }
+
+ public void startTransaction()
+ {
+
+ }
+
+ public void commitTransaction()
+ {
+
+ }
+
+ public void rollbackTransaction()
+ {
+
+ }
+
+ public boolean isTransactionActive()
+ {
+ return false;
+ }
+ };
+ }
+
+ public String getRealmId()
+ {
+ return "testRealm";
+ }
+ };
+
+ //populate();
+
+ store = new LDAPIdentityStoreImpl("LDAPTestStore");
+
+ store.bootstrap(storeMD);
+ }
+
+ protected void tearDown() throws Exception
+ {
+ super.tearDown();
+
+ cleanUp();
+
+ openDSService.stop();
+ }
+
+ public void begin() throws Exception
+ {
+ //nothing
+ }
+
+ public void commit() throws Exception
+ {
+ //nothing
+ }
+
+ public void flush() throws Exception
+ {
+ //nothing
+ }
+
+ public IdentityStore getStore()
+ {
+ return store;
+ }
+
+ public IdentityStoreInvocationContext getCtx()
+ {
+ return ctx;
+ }
+
+
+ public LdapContext getLdapContext() throws Exception
+ {
+ Hashtable<String,String> env = new Hashtable<String,String>();
+ env.put(Context.INITIAL_CONTEXT_FACTORY, "com.sun.jndi.ldap.LdapCtxFactory");
+ env.put(Context.PROVIDER_URL, LDAP_PROVIDER_URL);
+ env.put(Context.SECURITY_AUTHENTICATION, "simple");
+ env.put(Context.SECURITY_PRINCIPAL, LDAP_PRINCIPAL);
+ env.put(Context.SECURITY_CREDENTIALS, LDAP_CREDENTIALS);
+
+ return new InitialLdapContext(env, null);
+ }
+
+
+
+ public void populate() throws Exception
+ {
+ populateLDIF("target/test-classes/ldap/initial-opends.ldif");
+ }
+
+ public void populateClean() throws Exception
+ {
+ populateLDIF("target/test-classes/ldap/initial-empty-opends.ldif");
+ }
+
+ public void populateLDIF(String ldifRelativePath) throws Exception
+ {
+ File ldif = new File(ldifRelativePath);
+
+ System.out.println("LDIF: " + ldif.getAbsolutePath());
+
+ String[] cmd = new String[] {"-h", LDAP_HOST,
+ "-p", LDAP_PORT,
+ "-D", LDAP_PRINCIPAL,
+ "-w", LDAP_CREDENTIALS,
+ "-a", "-f", ldif.getPath()};
+
+ System.out.println("Populate success: " + (LDAPModify.mainModify(cmd, false, System.out, System.err) == 0));
+
+ }
+
+ protected void cleanUp() throws Exception
+ {
+ DirContext ldapCtx = getLdapContext();
+
+ try
+ {
+
+
+ String dn = "dc=portal,dc=example,dc=com";
+
+ System.out.println("Removing: " + dn);
+
+ removeContext(ldapCtx, dn);
+ }
+ catch (Exception e)
+ {
+ //
+ }
+ finally
+ {
+ ldapCtx.close();
+ }
+ }
+
+ //subsequent remove of javax.naming.Context
+ protected void removeContext(Context mainCtx, String name) throws Exception
+ {
+ Context deleteCtx = (Context)mainCtx.lookup(name);
+ NamingEnumeration subDirs = mainCtx.listBindings(name);
+
+ while (subDirs.hasMoreElements())
+ {
+ Binding binding = (Binding)subDirs.nextElement();
+ String subName = binding.getName();
+
+ removeContext(deleteCtx, subName);
+ }
+
+ mainCtx.unbind(name);
+ }
+
+ // Tests
+
+// Just test if OpenDS is running and was populated...
+ public void testSimple() throws Exception
+ {
+ populate();
+
+ Hashtable<String,String> env = new Hashtable<String,String>();
+ env.put(Context.INITIAL_CONTEXT_FACTORY, "com.sun.jndi.ldap.LdapCtxFactory");
+ env.put(Context.PROVIDER_URL, LDAP_PROVIDER_URL);
+ env.put(Context.SECURITY_AUTHENTICATION, "simple");
+ env.put(Context.SECURITY_PRINCIPAL, LDAP_PRINCIPAL);
+ env.put(Context.SECURITY_CREDENTIALS, LDAP_CREDENTIALS);
+
+ LdapContext ldapCtx = null;
+ try
+ {
+ ldapCtx = new InitialLdapContext(env, null);
+
+// Do something ...
+ System.out.println("Attributes: " + ldapCtx.getAttributes("o=test,dc=portal,dc=example,dc=com"));
+
+ }
+ catch (NamingException e)
+ {
+ e.printStackTrace();
+ }
+ finally
+ {
+ try
+ {
+ if (ldapCtx != null)
+ {
+ ldapCtx.close();
+ }
+ }
+ catch (NamingException e)
+ {
+ e.printStackTrace();
+ }
+ }
+ }
+
+ public void testIdentityObjectCount() throws Exception
+ {
+ populate();
+
+ assertEquals(7, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.IDENTITY));
+ assertEquals(5, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.ROLE));
+ assertEquals(2, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.GROUP));
+ }
+
+ public void testFindCreateRemove() throws Exception
+ {
+ populate();
+
+ assertEquals(7, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.IDENTITY));
+
+ IdentityObject io = store.findIdentityObject(ctx, "admin", IdentityTypeEnum.IDENTITY);
+ assertEquals("admin", io.getName());
+ assertEquals("uid=admin,ou=People,o=test,dc=portal,dc=example,dc=com", io.getId().toString());
+
+ //
+
+ store.removeIdentityObject(ctx, io);
+
+ assertEquals(6, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.IDENTITY));
+
+ store.createIdentityObject(ctx, "newUserA", IdentityTypeEnum.IDENTITY);
+
+ assertEquals(7, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.IDENTITY));
+
+ //
+
+ assertEquals(2, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.GROUP));
+
+ store.createIdentityObject(ctx, "newGroupA", IdentityTypeEnum.GROUP);
+
+ assertEquals(3, store.getIdentityObjectsCount(ctx, IdentityTypeEnum.GROUP));
+
+ //
+
+ io = store.findIdentityObject(ctx, "cn=newGroupA,ou=Groups,o=test,dc=portal,dc=example,dc=com");
+ assertEquals("newGroupA", io.getName());
+
+ }
+
+ public void testAttributes() throws Exception{
+
+ populate();
+
+ IdentityObject user1 = store.createIdentityObject(ctx, "Adam", IdentityTypeEnum.IDENTITY);
+ IdentityObject user2 = store.createIdentityObject(ctx, "Eva", IdentityTypeEnum.IDENTITY);
+
+ //
+
+ Map<String, String[]> attrs = new HashMap<String, String[]>();
+
+
+ attrs.put("phone", new String[]{"val1", "val2", "val3"});
+ attrs.put("description", new String[]{"val1", "val2", "val3", "val4"});
+
+ store.addAttributes(ctx, user1, attrs);
+
+ //
+
+ Map<String, String[]> persistedAttrs = store.getAttributes(ctx, user1);
+
+ assertEquals(2, persistedAttrs.keySet().size());
+
+ assertTrue(persistedAttrs.containsKey("phone"));
+ assertEquals(3, persistedAttrs.get("phone").length);
+
+ assertTrue(persistedAttrs.containsKey("description"));
+ assertEquals(4, persistedAttrs.get("description").length);
+
+ //
+
+ attrs = new HashMap<String, String[]>();
+ attrs.put("carLicense", new String[]{"val1"});
+
+ store.addAttributes(ctx, user1, attrs);
+
+ //
+
+ persistedAttrs = store.getAttributes(ctx, user1);
+
+ assertEquals(3, persistedAttrs.keySet().size());
+
+ assertTrue(persistedAttrs.containsKey("phone"));
+ assertEquals(3, persistedAttrs.get("phone").length);
+
+ assertTrue(persistedAttrs.containsKey("description"));
+ assertEquals(4, persistedAttrs.get("description").length);
+
+ assertTrue(persistedAttrs.containsKey("carLicense"));
+ assertEquals(1, persistedAttrs.get("carLicense").length);
+
+ attrs.put("carLicense", new String[]{"val2"});
+
+ store.addAttributes(ctx, user1, attrs);
+
+ //
+
+ persistedAttrs = store.getAttributes(ctx, user1);
+
+ assertEquals(3, persistedAttrs.keySet().size());
+
+ assertTrue(persistedAttrs.containsKey("carLicense"));
+ assertEquals(2, persistedAttrs.get("carLicense").length);
+
+ //
+
+ store.updateAttributes(ctx, user1, attrs);
+
+ //
+
+ persistedAttrs = store.getAttributes(ctx, user1);
+
+ assertEquals(3, persistedAttrs.keySet().size());
+
+ assertTrue(persistedAttrs.containsKey("carLicense"));
+ assertEquals(1, persistedAttrs.get("carLicense").length);
+
+ //
+
+ String[] names = new String[]{"carLicense"};
+ store.removeAttributes(ctx, user1, names);
+
+ //
+
+ persistedAttrs = store.getAttributes(ctx, user1);
+
+ assertEquals(2, persistedAttrs.keySet().size());
+
+ }
+
+ public void testRelationships() throws Exception
+ {
+ populateClean();
+
+ commonTest.testRelationships();
+
+ }
+
+ public void testStorePersistence() throws Exception
+ {
+ populateClean();
+
+ commonTest.testStorePersistence();
+
+ }
+
+ public void testFindMethods() throws Exception
+ {
+ populateClean();
+
+ commonTest.testFindMethods();
+
+ }
+
+ public void testControls() throws Exception
+ {
+ populateClean();
+
+ commonTest.testControls();
+ }
+
+}
Modified: trunk/identity-impl/src/test/resources/ldap/initial-empty-opends.ldif
===================================================================
--- trunk/identity-impl/src/test/resources/ldap/initial-empty-opends.ldif 2008-12-02 18:51:34 UTC (rev 124)
+++ trunk/identity-impl/src/test/resources/ldap/initial-empty-opends.ldif 2008-12-04 09:52:41 UTC (rev 125)
@@ -28,5 +28,5 @@
dn: ou=Organizations,o=test,dc=portal,dc=example,dc=com
objectclass: top
objectclass: organizationalUnit
-ou: Groups
+ou: Organizations
Modified: trunk/identity-impl/src/test/resources/ldap/initial-opends.ldif
===================================================================
--- trunk/identity-impl/src/test/resources/ldap/initial-opends.ldif 2008-12-02 18:51:34 UTC (rev 124)
+++ trunk/identity-impl/src/test/resources/ldap/initial-opends.ldif 2008-12-04 09:52:41 UTC (rev 125)
@@ -163,3 +163,8 @@
description: Some organization
member: cn=User,ou=Roles,o=test,dc=portal,dc=example,dc=com
member: cn=Admin,ou=Roles,o=test,dc=portal,dc=example,dc=com
+
+dn: ou=Organizations,o=test,dc=portal,dc=example,dc=com
+objectclass: top
+objectclass: organizationalUnit
+ou: Organization
Modified: trunk/identity-impl/src/test/resources/store-test-config.xml
===================================================================
--- trunk/identity-impl/src/test/resources/store-test-config.xml 2008-12-02 18:51:34 UTC (rev 124)
+++ trunk/identity-impl/src/test/resources/store-test-config.xml 2008-12-04 09:52:41 UTC (rev 125)
@@ -161,7 +161,9 @@
<id>LDAPTestStore</id>
<class>org.jboss.identity.impl.store.ldap.LDAPIdentityStoreImpl</class>
<external-config/>
- <supported-relationship-types/>
+ <supported-relationship-types>
+ <relationship-type>JBOSS_IDENTITY_MEMBERSHIP</relationship-type>
+ </supported-relationship-types>
<supported-identity-object-types>
<identity-object-type>
<name>IDENTITY</name>
@@ -218,17 +220,21 @@
<name>GROUP</name>
<relationships>
<relationship>
- <relationship-type-ref/>
+ <relationship-type-ref>JBOSS_IDENTITY_MEMBERSHIP</relationship-type-ref>
<identity-object-type-ref>IDENTITY</identity-object-type-ref>
</relationship>
<relationship>
- <relationship-type-ref/>
+ <relationship-type-ref>JBOSS_IDENTITY_MEMBERSHIP</relationship-type-ref>
<identity-object-type-ref>ROLE</identity-object-type-ref>
</relationship>
<relationship>
- <relationship-type-ref/>
+ <relationship-type-ref>JBOSS_IDENTITY_MEMBERSHIP</relationship-type-ref>
<identity-object-type-ref>GROUP</identity-object-type-ref>
</relationship>
+ <relationship>
+ <relationship-type-ref>JBOSS_IDENTITY_MEMBERSHIP</relationship-type-ref>
+ <identity-object-type-ref>ORGANIZATION</identity-object-type-ref>
+ </relationship>
</relationships>
<credentials/>
<attributes/>
@@ -239,7 +245,7 @@
</option>
<option>
<name>ctxDNs</name>
- <value>ou=Roles,o=test,dc=portal,dc=example,dc=com</value>
+ <value>ou=Groups,o=test,dc=portal,dc=example,dc=com</value>
</option>
<!--<option>-->
<!--<name>entrySearchFilter</name>-->
@@ -269,10 +275,68 @@
</options>
</identity-object-type>
<identity-object-type>
+ <name>ORGANIZATION</name>
+ <relationships>
+ <relationship>
+ <relationship-type-ref>JBOSS_IDENTITY_MEMBERSHIP</relationship-type-ref>
+ <identity-object-type-ref>IDENTITY</identity-object-type-ref>
+ </relationship>
+ <relationship>
+ <relationship-type-ref>JBOSS_IDENTITY_MEMBERSHIP</relationship-type-ref>
+ <identity-object-type-ref>ROLE</identity-object-type-ref>
+ </relationship>
+ <relationship>
+ <relationship-type-ref>JBOSS_IDENTITY_MEMBERSHIP</relationship-type-ref>
+ <identity-object-type-ref>GROUP</identity-object-type-ref>
+ </relationship>
+ <relationship>
+ <relationship-type-ref>JBOSS_IDENTITY_MEMBERSHIP</relationship-type-ref>
+ <identity-object-type-ref>ORGANIZATION</identity-object-type-ref>
+ </relationship>
+ </relationships>
+ <credentials/>
+ <attributes/>
+ <options>
+ <option>
+ <name>idAttributeName</name>
+ <value>cn</value>
+ </option>
+ <option>
+ <name>ctxDNs</name>
+ <value>ou=Organizations,o=test,dc=portal,dc=example,dc=com</value>
+ </option>
+ <!--<option>-->
+ <!--<name>entrySearchFilter</name>-->
+ <!--<value></value>-->
+ <!--</option>-->
+ <option>
+ <name>allowCreateEntry</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>membershipAttributeName</name>
+ <value>member</value>
+ </option>
+ <option>
+ <name>isMembershipAttributeDN</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>allowEmptyMemberships</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>createEntryAttributeValues</name>
+ <value>objectClass=top</value>
+ <value>objectClass=groupOfNames</value>
+ </option>
+ </options>
+ </identity-object-type>
+ <identity-object-type>
<name>ROLE</name>
<relationships>
<relationship>
- <relationship-type-ref/>
+ <relationship-type-ref>JBOSS_IDENTITY_MEMBERSHIP</relationship-type-ref>
<identity-object-type-ref>IDENTITY</identity-object-type-ref>
</relationship>
</relationships>
17 years, 7 months
JBoss Identity SVN: r124 - in trunk: identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2 and 14 other directories.
by jboss-identity-commits@lists.jboss.org
Author: bdaw
Date: 2008-12-02 13:51:34 -0500 (Tue, 02 Dec 2008)
New Revision: 124
Added:
trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/AbstractCredential.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/BinaryCredential.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/NameFilterSearchControl.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/PasswordCredential.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/SimpleCredentialTypeImpl.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/CredentialsType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectCredential.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectCredentialType.java
trunk/identity-impl/src/test/resources/store-test-config.xml
Modified:
trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/AttributeFilterSearchControl.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/PageSearchControl.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/SortByNameSearchControl.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/JAXB2IdentityConfiguration.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/AttributeType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/AttributesType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/ExternalConfigType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/GroupTypeMappingType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityObjectTypeType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityObjectTypesType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreMappingType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreMappingsType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoresType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityTypeMappingsType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/JbossIdentityType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/ObjectFactory.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/OptionType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/OptionsType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RealmType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RealmsType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RelationshipType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RelationshipsType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RepositoriesType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RepositoryType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/StoresType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/SupportedIdentityObjectTypesType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/SupportedRelationshipTypesType.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/package-info.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/metadata/IdentityObjectTypeMetaDataImpl.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObject.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectAttribute.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectRelationshipName.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateRealm.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/repository/WrapperIdentityStoreRepository.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/FeaturesMetaDataImpl.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/hibernate/HibernateIdentityStoreImpl.java
trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreImpl.java
trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/CommonIdentityStoreTest.java
trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/RelationshipTypeEnum.java
trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/hibernate/HibernateIdentityStoreTestCase.java
trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/hibernate/HibernateModelTestCase.java
trunk/identity-impl/src/test/resources/META-INF/persistence.xml
trunk/identity-impl/src/test/resources/identity-config.xml
trunk/identity-impl/src/test/resources/identity-config.xsd
trunk/identity-impl/src/test/resources/organization-test-config.xml
trunk/identity-spi/src/main/java/org/jboss/identity/spi/configuration/metadata/IdentityObjectTypeMetaData.java
trunk/identity-spi/src/main/java/org/jboss/identity/spi/credential/IdentityObjectCredential.java
trunk/identity-spi/src/main/java/org/jboss/identity/spi/store/FeaturesMetaData.java
Log:
Nearly feature complete Hibernate store
Added: trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/AbstractCredential.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/AbstractCredential.java (rev 0)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/AbstractCredential.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -0,0 +1,46 @@
+/*
+* JBoss, a division of Red Hat
+* Copyright 2006, Red Hat Middleware, LLC, and individual contributors as indicated
+* by the @authors tag. See the copyright.txt in the distribution for a
+* full listing of individual contributors.
+*
+* This is free software; you can redistribute it and/or modify it
+* under the terms of the GNU Lesser General Public License as
+* published by the Free Software Foundation; either version 2.1 of
+* the License, or (at your option) any later version.
+*
+* This software is distributed in the hope that it will be useful,
+* but WITHOUT ANY WARRANTY; without even the implied warranty of
+* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+* Lesser General Public License for more details.
+*
+* You should have received a copy of the GNU Lesser General Public
+* License along with this software; if not, write to the Free
+* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
+* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
+*/
+
+package org.jboss.identity.impl.api;
+
+import org.jboss.identity.spi.credential.IdentityObjectCredential;
+import org.jboss.identity.api.Credential;
+import org.jboss.identity.api.CredentialType;
+
+/**
+ * @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
+ * @version : 0.1 $
+ */
+public abstract class AbstractCredential implements Credential, IdentityObjectCredential
+{
+ private final SimpleCredentialTypeImpl type;
+
+ public AbstractCredential(SimpleCredentialTypeImpl type)
+ {
+ this.type = type;
+ }
+
+ public SimpleCredentialTypeImpl getType()
+ {
+ return type;
+ }
+}
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/AttributeFilterSearchControl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/AttributeFilterSearchControl.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/AttributeFilterSearchControl.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -25,11 +25,27 @@
import org.jboss.identity.api.IdentitySearchControl;
import org.jboss.identity.spi.searchcontrol.IdentityObjectSearchControl;
+import java.util.Map;
+
/**
* @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
* @version : 0.1 $
*/
public class AttributeFilterSearchControl implements IdentitySearchControl, IdentityObjectSearchControl
{
-
+ private final Map<String, String[]> attributes;
+
+ public AttributeFilterSearchControl(Map<String, String[]> attributes)
+ {
+ if (attributes == null)
+ {
+ throw new IllegalArgumentException("attributes is null");
+ }
+ this.attributes = attributes;
+ }
+
+ public Map<String, String[]> getValues()
+ {
+ return attributes;
+ }
}
Added: trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/BinaryCredential.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/BinaryCredential.java (rev 0)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/BinaryCredential.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -0,0 +1,48 @@
+/*
+* JBoss, a division of Red Hat
+* Copyright 2006, Red Hat Middleware, LLC, and individual contributors as indicated
+* by the @authors tag. See the copyright.txt in the distribution for a
+* full listing of individual contributors.
+*
+* This is free software; you can redistribute it and/or modify it
+* under the terms of the GNU Lesser General Public License as
+* published by the Free Software Foundation; either version 2.1 of
+* the License, or (at your option) any later version.
+*
+* This software is distributed in the hope that it will be useful,
+* but WITHOUT ANY WARRANTY; without even the implied warranty of
+* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+* Lesser General Public License for more details.
+*
+* You should have received a copy of the GNU Lesser General Public
+* License along with this software; if not, write to the Free
+* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
+* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
+*/
+
+package org.jboss.identity.impl.api;
+
+/**
+ * @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
+ * @version : 0.1 $
+ */
+public class BinaryCredential extends AbstractCredential
+{
+ private final byte[] value;
+
+ public BinaryCredential(byte[] value)
+ {
+ super(new SimpleCredentialTypeImpl("BINARY"));
+ this.value = value;
+ }
+
+ public byte[] getValue()
+ {
+ return value;
+ }
+
+ public Object getEncodedValue()
+ {
+ return null;
+ }
+}
\ No newline at end of file
Added: trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/NameFilterSearchControl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/NameFilterSearchControl.java (rev 0)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/NameFilterSearchControl.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -0,0 +1,46 @@
+/*
+* JBoss, a division of Red Hat
+* Copyright 2006, Red Hat Middleware, LLC, and individual contributors as indicated
+* by the @authors tag. See the copyright.txt in the distribution for a
+* full listing of individual contributors.
+*
+* This is free software; you can redistribute it and/or modify it
+* under the terms of the GNU Lesser General Public License as
+* published by the Free Software Foundation; either version 2.1 of
+* the License, or (at your option) any later version.
+*
+* This software is distributed in the hope that it will be useful,
+* but WITHOUT ANY WARRANTY; without even the implied warranty of
+* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+* Lesser General Public License for more details.
+*
+* You should have received a copy of the GNU Lesser General Public
+* License along with this software; if not, write to the Free
+* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
+* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
+*/
+
+package org.jboss.identity.impl.api;
+
+import org.jboss.identity.api.IdentitySearchControl;
+import org.jboss.identity.spi.searchcontrol.IdentityObjectSearchControl;
+
+/**
+ * @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
+ * @version : 0.1 $
+ */
+public class NameFilterSearchControl implements IdentitySearchControl, IdentityObjectSearchControl
+{
+
+ private final String filter;
+
+ public NameFilterSearchControl(String filter)
+ {
+ this.filter = filter;
+ }
+
+ public String getFilter()
+ {
+ return filter;
+ }
+}
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/PageSearchControl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/PageSearchControl.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/PageSearchControl.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -31,9 +31,9 @@
*/
public class PageSearchControl implements IdentitySearchControl, IdentityObjectSearchControl
{
- private int offset;
+ private final int offset;
- private int limit;
+ private final int limit;
public PageSearchControl(int offset, int limit)
{
@@ -46,18 +46,8 @@
return offset;
}
- public void setOffset(int offset)
- {
- this.offset = offset;
- }
-
public int getLimit()
{
return limit;
}
-
- public void setLimit(int limit)
- {
- this.limit = limit;
- }
}
Added: trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/PasswordCredential.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/PasswordCredential.java (rev 0)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/PasswordCredential.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -0,0 +1,120 @@
+/*
+* JBoss, a division of Red Hat
+* Copyright 2006, Red Hat Middleware, LLC, and individual contributors as indicated
+* by the @authors tag. See the copyright.txt in the distribution for a
+* full listing of individual contributors.
+*
+* This is free software; you can redistribute it and/or modify it
+* under the terms of the GNU Lesser General Public License as
+* published by the Free Software Foundation; either version 2.1 of
+* the License, or (at your option) any later version.
+*
+* This software is distributed in the hope that it will be useful,
+* but WITHOUT ANY WARRANTY; without even the implied warranty of
+* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+* Lesser General Public License for more details.
+*
+* You should have received a copy of the GNU Lesser General Public
+* License along with this software; if not, write to the Free
+* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
+* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
+*/
+
+package org.jboss.identity.impl.api;
+
+import java.security.MessageDigest;
+import java.security.NoSuchAlgorithmException;
+
+/**
+ * @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
+ * @version : 0.1 $
+ */
+public class PasswordCredential extends AbstractCredential
+{
+ private final String value;
+
+ public PasswordCredential(String value)
+ {
+ super(new SimpleCredentialTypeImpl("PASSWORD"));
+ this.value = value;
+ }
+
+ public String getValue()
+ {
+ return value;
+ }
+
+ public Object getEncodedValue()
+ {
+ if (value != null)
+ {
+ return md5AsHexString(getValue());
+ }
+ return null;
+ }
+
+ /**
+ * Computes an md5 hash of a string.
+ *
+ * @param text the hashed string
+ * @return the string hash
+ * @throws NullPointerException if text is null
+ */
+ public static byte[] md5(String text)
+ {
+ // arguments check
+ if (text == null)
+ {
+ throw new NullPointerException("null text");
+ }
+
+ try
+ {
+ MessageDigest md = MessageDigest.getInstance("MD5");
+ md.update(text.getBytes());
+ return md.digest();
+ }
+ catch (NoSuchAlgorithmException e)
+ {
+
+ throw new RuntimeException("Cannot find MD5 algorithm");
+ }
+ }
+
+ /**
+ * Computes an md5 hash and returns the result as a string in hexadecimal format.
+ *
+ * @param text the hashed string
+ * @return the string hash
+ * @throws NullPointerException if text is null
+ */
+ public static String md5AsHexString(String text)
+ {
+ return toHexString(md5(text));
+ }
+
+/**
+ * Returns a string in the hexadecimal format.
+ *
+ * @param bytes the converted bytes
+ * @return the hexadecimal string representing the bytes data
+ * @throws IllegalArgumentException if the byte array is null
+ */
+ public static String toHexString(byte[] bytes)
+ {
+ if (bytes == null)
+ {
+ throw new IllegalArgumentException("byte array must not be null");
+ }
+ StringBuffer hex = new StringBuffer(bytes.length * 2);
+ for (int i = 0; i < bytes.length; i++)
+ {
+ hex.append(Character.forDigit((bytes[i] & 0XF0) >> 4, 16));
+ hex.append(Character.forDigit((bytes[i] & 0X0F), 16));
+ }
+ return hex.toString();
+ }
+
+
+
+}
Added: trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/SimpleCredentialTypeImpl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/SimpleCredentialTypeImpl.java (rev 0)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/SimpleCredentialTypeImpl.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -0,0 +1,46 @@
+/*
+* JBoss, a division of Red Hat
+* Copyright 2006, Red Hat Middleware, LLC, and individual contributors as indicated
+* by the @authors tag. See the copyright.txt in the distribution for a
+* full listing of individual contributors.
+*
+* This is free software; you can redistribute it and/or modify it
+* under the terms of the GNU Lesser General Public License as
+* published by the Free Software Foundation; either version 2.1 of
+* the License, or (at your option) any later version.
+*
+* This software is distributed in the hope that it will be useful,
+* but WITHOUT ANY WARRANTY; without even the implied warranty of
+* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+* Lesser General Public License for more details.
+*
+* You should have received a copy of the GNU Lesser General Public
+* License along with this software; if not, write to the Free
+* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
+* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
+*/
+
+package org.jboss.identity.impl.api;
+
+import org.jboss.identity.api.CredentialType;
+import org.jboss.identity.spi.credential.IdentityObjectCredentialType;
+
+/**
+ * @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
+ * @version : 0.1 $
+ */
+public class SimpleCredentialTypeImpl implements CredentialType, IdentityObjectCredentialType
+{
+ private final String name;
+
+ public SimpleCredentialTypeImpl(String name)
+ {
+ this.name = name;
+ }
+
+ public String getName()
+ {
+ return name;
+ }
+}
+
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/SortByNameSearchControl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/SortByNameSearchControl.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/api/SortByNameSearchControl.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -31,7 +31,7 @@
*/
public class SortByNameSearchControl implements IdentitySearchControl, IdentityObjectSearchControl
{
- private boolean ascending;
+ private final boolean ascending;
public SortByNameSearchControl(boolean ascending)
{
@@ -42,9 +42,4 @@
{
return ascending;
}
-
- public void setAscending(boolean ascending)
- {
- this.ascending = ascending;
- }
}
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/JAXB2IdentityConfiguration.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/JAXB2IdentityConfiguration.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/JAXB2IdentityConfiguration.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -141,7 +141,8 @@
Map<String, String> groupMappings = new HashMap<String, String>();
- if (realmType.getIdentityTypeMappings() != null)
+ if (realmType.getIdentityTypeMappings() != null
+ && realmType.getIdentityTypeMappings().getGroupTypeMapping() != null)
{
for (GroupTypeMappingType groupTypeMappingType : realmType.getIdentityTypeMappings().getGroupTypeMapping())
{
@@ -173,15 +174,20 @@
List<IdentityStoreMappingMetaData> storeMappings = new LinkedList<IdentityStoreMappingMetaData>();
- for (IdentityStoreMappingType identityStoreMappingType : repositoryType.getIdentityStoreMappings().getIdentityStoreMapping())
+ if (repositoryType.getIdentityStoreMappings() != null &&
+ repositoryType.getIdentityStoreMappings().getIdentityStoreMapping() != null)
{
- IdentityStoreMappingMetaDataImpl mapping = new IdentityStoreMappingMetaDataImpl();
- mapping.setIdentityStoreId(identityStoreMappingType.getIdentityStoreId());
- mapping.setIdentityObjectTypeMappings(identityStoreMappingType.getIdentityObjectTypes().getIdentityObjectType());
- mapping.setOptions(createOptions(identityStoreMappingType.getOptions()));
+ for (IdentityStoreMappingType identityStoreMappingType : repositoryType.getIdentityStoreMappings().getIdentityStoreMapping())
+ {
+ IdentityStoreMappingMetaDataImpl mapping = new IdentityStoreMappingMetaDataImpl();
- storeMappings.add(mapping);
+ mapping.setIdentityStoreId(identityStoreMappingType.getIdentityStoreId());
+ mapping.setIdentityObjectTypeMappings(identityStoreMappingType.getIdentityObjectTypes().getIdentityObjectType());
+ mapping.setOptions(createOptions(identityStoreMappingType.getOptions()));
+
+ storeMappings.add(mapping);
+ }
}
repoMD.setIdentityStoreToIdentityObjectTypeMappings(storeMappings);
@@ -206,66 +212,98 @@
storeMD.setSupportedRelationshipTypes(identityStoreType.getSupportedRelationshipTypes().getRelationshipType());
- for (IdentityObjectTypeType identityObjectTypeType : identityStoreType.getSupportedIdentityObjectTypes().getIdentityObjectType())
+ if (identityStoreType.getSupportedIdentityObjectTypes() != null &&
+ identityStoreType.getSupportedIdentityObjectTypes().getIdentityObjectType() != null)
+
{
- IdentityObjectTypeMetaDataImpl identityObjectTypeMD = new IdentityObjectTypeMetaDataImpl();
- identityObjectTypeMD.setName(identityObjectTypeType.getName());
+ for (IdentityObjectTypeType identityObjectTypeType : identityStoreType.getSupportedIdentityObjectTypes().getIdentityObjectType())
+ {
+ IdentityObjectTypeMetaDataImpl identityObjectTypeMD = new IdentityObjectTypeMetaDataImpl();
- List<AttributeMetaData> attributes = new LinkedList<AttributeMetaData>();
+ identityObjectTypeMD.setName(identityObjectTypeType.getName());
- for (AttributeType attributeType : identityObjectTypeType.getAttributes().getAttribute())
- {
- AttributeMetaDataImpl attributeMD = new AttributeMetaDataImpl();
+ List<AttributeMetaData> attributes = new LinkedList<AttributeMetaData>();
- attributeMD.setName(attributeType.getName());
- attributeMD.setStoreMapping(attributeType.getMapping());
-
- String readonly = attributeType.getIsReadOnly();
- if (readonly != null && readonly.equalsIgnoreCase("true"))
+ if (identityObjectTypeType.getAttributes() != null &&
+ identityObjectTypeType.getAttributes().getAttribute() != null)
{
- attributeMD.setReadonly(true);
- }
- String multivalued = attributeType.getIsMultivalued();
- if (multivalued != null && multivalued.equalsIgnoreCase("true"))
- {
- attributeMD.setMultivalued(true);
+ for (AttributeType attributeType : identityObjectTypeType.getAttributes().getAttribute())
+ {
+ AttributeMetaDataImpl attributeMD = new AttributeMetaDataImpl();
+
+ attributeMD.setName(attributeType.getName());
+ attributeMD.setStoreMapping(attributeType.getMapping());
+
+ String readonly = attributeType.getIsReadOnly();
+ if (readonly != null && readonly.equalsIgnoreCase("true"))
+ {
+ attributeMD.setReadonly(true);
+ }
+
+ String multivalued = attributeType.getIsMultivalued();
+ if (multivalued != null && multivalued.equalsIgnoreCase("true"))
+ {
+ attributeMD.setMultivalued(true);
+ }
+
+ String required = attributeType.getIsRequired();
+ if (required != null && required.equalsIgnoreCase("true"))
+ {
+ attributeMD.setRequired(true);
+ }
+
+ attributes.add(attributeMD);
+ }
}
- String required = attributeType.getIsRequired();
- if (required != null && required.equalsIgnoreCase("true"))
+ identityObjectTypeMD.setAttributes(attributes);
+
+ List<String> credentials = new LinkedList<String>();
+
+ if (identityObjectTypeType.getCredentials() != null &&
+ identityObjectTypeType.getCredentials().getCredentialType() != null)
{
- attributeMD.setRequired(true);
+ for (String credentialType : identityObjectTypeType.getCredentials().getCredentialType())
+ {
+ credentials.add(credentialType);
+ }
}
- attributes.add(attributeMD);
- }
+ identityObjectTypeMD.setCredentials(credentials);
- identityObjectTypeMD.setAttributes(attributes);
+ Map<String, List<String>> options = new HashMap<String, List<String>>();
+ if (identityObjectTypeType.getOptions() != null &&
+ identityObjectTypeType.getOptions().getOption() != null)
+ {
- Map<String, List<String>> options = new HashMap<String, List<String>>();
+ for (OptionType optionType : identityObjectTypeType.getOptions().getOption())
+ {
+ options.put(optionType.getName(), optionType.getValue());
+ }
+ }
+
+ identityObjectTypeMD.setOptions(options);
- for (OptionType optionType : identityObjectTypeType.getOptions().getOption())
- {
- options.put(optionType.getName(), optionType.getValue());
+ storeMD.getSupportedIdentityTypes().add(identityObjectTypeMD);
}
-
- identityObjectTypeMD.setOptions(options);
-
- storeMD.getSupportedIdentityTypes().add(identityObjectTypeMD);
}
-
Map<String, List<String>> options = new HashMap<String, List<String>>();
- for (OptionType optionType : identityStoreType.getOptions().getOption())
+ if (identityStoreType.getOptions() != null &&
+ identityStoreType.getOptions().getOption() != null)
{
- options.put(optionType.getName(), optionType.getValue());
+
+ for (OptionType optionType : identityStoreType.getOptions().getOption())
+ {
+ options.put(optionType.getName(), optionType.getValue());
+ }
}
-
+
storeMD.setOptions(options);
return storeMD;
@@ -275,7 +313,8 @@
{
Map<String, List<String>> options = new HashMap<String, List<String>>();
- if (optionsType != null)
+ if (optionsType != null &&
+ optionsType.getOption() != null)
{
for (OptionType optionType : optionsType.getOption())
{
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/AttributeType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/AttributeType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/AttributeType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
@@ -26,8 +26,24 @@
* <sequence>
* <element name="name" type="{http://www.w3.org/2001/XMLSchema}string"/>
* <element name="mapping" type="{http://www.w3.org/2001/XMLSchema}string"/>
- * <element name="isRequired" type="{http://www.w3.org/2001/XMLSchema}string"/>
- * <element name="isMultivalued" type="{http://www.w3.org/2001/XMLSchema}string"/>
+ * <element name="isRequired">
+ * <simpleType>
+ * <restriction base="{http://www.w3.org/2001/XMLSchema}string">
+ * <enumeration value=""/>
+ * <enumeration value="true"/>
+ * <enumeration value="false"/>
+ * </restriction>
+ * </simpleType>
+ * </element>
+ * <element name="isMultivalued">
+ * <simpleType>
+ * <restriction base="{http://www.w3.org/2001/XMLSchema}string">
+ * <enumeration value=""/>
+ * <enumeration value="true"/>
+ * <enumeration value="false"/>
+ * </restriction>
+ * </simpleType>
+ * </element>
* <element name="isReadOnly" type="{http://www.w3.org/2001/XMLSchema}string" minOccurs="0"/>
* </sequence>
* </restriction>
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/AttributesType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/AttributesType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/AttributesType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Added: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/CredentialsType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/CredentialsType.java (rev 0)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/CredentialsType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -0,0 +1,76 @@
+//
+// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
+// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
+// Any modifications to this file will be lost upon recompilation of the source schema.
+// Generated on: 2008.11.24 at 10:17:31 PM CET
+//
+
+
+package org.jboss.identity.impl.configuration.jaxb2.generated;
+
+import java.util.ArrayList;
+import java.util.List;
+import javax.xml.bind.annotation.XmlAccessType;
+import javax.xml.bind.annotation.XmlAccessorType;
+import javax.xml.bind.annotation.XmlElement;
+import javax.xml.bind.annotation.XmlType;
+
+
+/**
+ * <p>Java class for credentialsType complex type.
+ *
+ * <p>The following schema fragment specifies the expected content contained within this class.
+ *
+ * <pre>
+ * <complexType name="credentialsType">
+ * <complexContent>
+ * <restriction base="{http://www.w3.org/2001/XMLSchema}anyType">
+ * <sequence>
+ * <element name="credential-type" type="{http://www.w3.org/2001/XMLSchema}string" maxOccurs="unbounded" minOccurs="0"/>
+ * </sequence>
+ * </restriction>
+ * </complexContent>
+ * </complexType>
+ * </pre>
+ *
+ *
+ */
+(a)XmlAccessorType(XmlAccessType.FIELD)
+@XmlType(name = "credentialsType", propOrder = {
+ "credentialType"
+})
+public class CredentialsType {
+
+ @XmlElement(name = "credential-type")
+ protected List<String> credentialType;
+
+ /**
+ * Gets the value of the credentialType property.
+ *
+ * <p>
+ * This accessor method returns a reference to the live list,
+ * not a snapshot. Therefore any modification you make to the
+ * returned list will be present inside the JAXB object.
+ * This is why there is not a <CODE>set</CODE> method for the credentialType property.
+ *
+ * <p>
+ * For example, to add a new item, do as follows:
+ * <pre>
+ * getCredentialType().add(newItem);
+ * </pre>
+ *
+ *
+ * <p>
+ * Objects of the following type(s) are allowed in the list
+ * {@link String }
+ *
+ *
+ */
+ public List<String> getCredentialType() {
+ if (credentialType == null) {
+ credentialType = new ArrayList<String>();
+ }
+ return this.credentialType;
+ }
+
+}
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/ExternalConfigType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/ExternalConfigType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/ExternalConfigType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/GroupTypeMappingType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/GroupTypeMappingType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/GroupTypeMappingType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityObjectTypeType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityObjectTypeType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityObjectTypeType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
@@ -38,6 +38,17 @@
* </complexContent>
* </complexType>
* </element>
+ * <element name="credentials">
+ * <complexType>
+ * <complexContent>
+ * <restriction base="{http://www.w3.org/2001/XMLSchema}anyType">
+ * <sequence>
+ * <element name="credential-type" type="{http://www.w3.org/2001/XMLSchema}string" maxOccurs="unbounded" minOccurs="0"/>
+ * </sequence>
+ * </restriction>
+ * </complexContent>
+ * </complexType>
+ * </element>
* <element name="attributes">
* <complexType>
* <complexContent>
@@ -72,6 +83,7 @@
@XmlType(name = "identity-object-typeType", propOrder = {
"name",
"relationships",
+ "credentials",
"attributes",
"options"
})
@@ -82,6 +94,8 @@
@XmlElement(required = true)
protected IdentityObjectTypeType.Relationships relationships;
@XmlElement(required = true)
+ protected IdentityObjectTypeType.Credentials credentials;
+ @XmlElement(required = true)
protected IdentityObjectTypeType.Attributes attributes;
@XmlElement(required = true)
protected IdentityObjectTypeType.Options options;
@@ -135,6 +149,30 @@
}
/**
+ * Gets the value of the credentials property.
+ *
+ * @return
+ * possible object is
+ * {@link IdentityObjectTypeType.Credentials }
+ *
+ */
+ public IdentityObjectTypeType.Credentials getCredentials() {
+ return credentials;
+ }
+
+ /**
+ * Sets the value of the credentials property.
+ *
+ * @param value
+ * allowed object is
+ * {@link IdentityObjectTypeType.Credentials }
+ *
+ */
+ public void setCredentials(IdentityObjectTypeType.Credentials value) {
+ this.credentials = value;
+ }
+
+ /**
* Gets the value of the attributes property.
*
* @return
@@ -252,6 +290,66 @@
* <complexContent>
* <restriction base="{http://www.w3.org/2001/XMLSchema}anyType">
* <sequence>
+ * <element name="credential-type" type="{http://www.w3.org/2001/XMLSchema}string" maxOccurs="unbounded" minOccurs="0"/>
+ * </sequence>
+ * </restriction>
+ * </complexContent>
+ * </complexType>
+ * </pre>
+ *
+ *
+ */
+ @XmlAccessorType(XmlAccessType.FIELD)
+ @XmlType(name = "", propOrder = {
+ "credentialType"
+ })
+ public static class Credentials {
+
+ @XmlElement(name = "credential-type")
+ protected List<String> credentialType;
+
+ /**
+ * Gets the value of the credentialType property.
+ *
+ * <p>
+ * This accessor method returns a reference to the live list,
+ * not a snapshot. Therefore any modification you make to the
+ * returned list will be present inside the JAXB object.
+ * This is why there is not a <CODE>set</CODE> method for the credentialType property.
+ *
+ * <p>
+ * For example, to add a new item, do as follows:
+ * <pre>
+ * getCredentialType().add(newItem);
+ * </pre>
+ *
+ *
+ * <p>
+ * Objects of the following type(s) are allowed in the list
+ * {@link String }
+ *
+ *
+ */
+ public List<String> getCredentialType() {
+ if (credentialType == null) {
+ credentialType = new ArrayList<String>();
+ }
+ return this.credentialType;
+ }
+
+ }
+
+
+ /**
+ * <p>Java class for anonymous complex type.
+ *
+ * <p>The following schema fragment specifies the expected content contained within this class.
+ *
+ * <pre>
+ * <complexType>
+ * <complexContent>
+ * <restriction base="{http://www.w3.org/2001/XMLSchema}anyType">
+ * <sequence>
* <element name="option" type="{urn:jboss:identity:config:v0_1}optionType" maxOccurs="unbounded" minOccurs="0"/>
* </sequence>
* </restriction>
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityObjectTypesType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityObjectTypesType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityObjectTypesType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreMappingType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreMappingType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreMappingType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreMappingsType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreMappingsType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreMappingsType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoreType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoresType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoresType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityStoresType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityTypeMappingsType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityTypeMappingsType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/IdentityTypeMappingsType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/JbossIdentityType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/JbossIdentityType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/JbossIdentityType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/ObjectFactory.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/ObjectFactory.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/ObjectFactory.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
@@ -41,14 +41,6 @@
}
/**
- * Create an instance of {@link RelationshipsType }
- *
- */
- public RelationshipsType createRelationshipsType() {
- return new RelationshipsType();
- }
-
- /**
* Create an instance of {@link IdentityObjectTypeType }
*
*/
@@ -57,131 +49,131 @@
}
/**
- * Create an instance of {@link IdentityTypeMappingsType }
+ * Create an instance of {@link IdentityObjectTypesType }
*
*/
- public IdentityTypeMappingsType createIdentityTypeMappingsType() {
- return new IdentityTypeMappingsType();
+ public IdentityObjectTypesType createIdentityObjectTypesType() {
+ return new IdentityObjectTypesType();
}
/**
- * Create an instance of {@link OptionsType }
+ * Create an instance of {@link IdentityStoresType }
*
*/
- public OptionsType createOptionsType() {
- return new OptionsType();
+ public IdentityStoresType createIdentityStoresType() {
+ return new IdentityStoresType();
}
/**
- * Create an instance of {@link IdentityObjectTypeType.Options }
+ * Create an instance of {@link IdentityStoreType.Options }
*
*/
- public IdentityObjectTypeType.Options createIdentityObjectTypeTypeOptions() {
- return new IdentityObjectTypeType.Options();
+ public IdentityStoreType.Options createIdentityStoreTypeOptions() {
+ return new IdentityStoreType.Options();
}
/**
- * Create an instance of {@link RepositoriesType }
+ * Create an instance of {@link SupportedRelationshipTypesType }
*
*/
- public RepositoriesType createRepositoriesType() {
- return new RepositoriesType();
+ public SupportedRelationshipTypesType createSupportedRelationshipTypesType() {
+ return new SupportedRelationshipTypesType();
}
/**
- * Create an instance of {@link IdentityObjectTypesType }
+ * Create an instance of {@link CredentialsType }
*
*/
- public IdentityObjectTypesType createIdentityObjectTypesType() {
- return new IdentityObjectTypesType();
+ public CredentialsType createCredentialsType() {
+ return new CredentialsType();
}
/**
- * Create an instance of {@link SupportedRelationshipTypesType }
+ * Create an instance of {@link RealmsType }
*
*/
- public SupportedRelationshipTypesType createSupportedRelationshipTypesType() {
- return new SupportedRelationshipTypesType();
+ public RealmsType createRealmsType() {
+ return new RealmsType();
}
/**
- * Create an instance of {@link ExternalConfigType }
+ * Create an instance of {@link StoresType }
*
*/
- public ExternalConfigType createExternalConfigType() {
- return new ExternalConfigType();
+ public StoresType createStoresType() {
+ return new StoresType();
}
/**
- * Create an instance of {@link AttributeType }
+ * Create an instance of {@link IdentityStoreMappingType }
*
*/
- public AttributeType createAttributeType() {
- return new AttributeType();
+ public IdentityStoreMappingType createIdentityStoreMappingType() {
+ return new IdentityStoreMappingType();
}
/**
- * Create an instance of {@link RealmsType }
+ * Create an instance of {@link IdentityObjectTypeType.Options }
*
*/
- public RealmsType createRealmsType() {
- return new RealmsType();
+ public IdentityObjectTypeType.Options createIdentityObjectTypeTypeOptions() {
+ return new IdentityObjectTypeType.Options();
}
/**
- * Create an instance of {@link AttributesType }
+ * Create an instance of {@link RepositoriesType }
*
*/
- public AttributesType createAttributesType() {
- return new AttributesType();
+ public RepositoriesType createRepositoriesType() {
+ return new RepositoriesType();
}
/**
- * Create an instance of {@link IdentityObjectTypeType.Attributes }
+ * Create an instance of {@link GroupTypeMappingType }
*
*/
- public IdentityObjectTypeType.Attributes createIdentityObjectTypeTypeAttributes() {
- return new IdentityObjectTypeType.Attributes();
+ public GroupTypeMappingType createGroupTypeMappingType() {
+ return new GroupTypeMappingType();
}
/**
- * Create an instance of {@link RelationshipType }
+ * Create an instance of {@link IdentityStoreMappingsType }
*
*/
- public RelationshipType createRelationshipType() {
- return new RelationshipType();
+ public IdentityStoreMappingsType createIdentityStoreMappingsType() {
+ return new IdentityStoreMappingsType();
}
/**
- * Create an instance of {@link IdentityStoreType.Options }
+ * Create an instance of {@link IdentityStoreType }
*
*/
- public IdentityStoreType.Options createIdentityStoreTypeOptions() {
- return new IdentityStoreType.Options();
+ public IdentityStoreType createIdentityStoreType() {
+ return new IdentityStoreType();
}
/**
- * Create an instance of {@link IdentityStoreType }
+ * Create an instance of {@link RealmType }
*
*/
- public IdentityStoreType createIdentityStoreType() {
- return new IdentityStoreType();
+ public RealmType createRealmType() {
+ return new RealmType();
}
/**
- * Create an instance of {@link StoresType }
+ * Create an instance of {@link OptionType }
*
*/
- public StoresType createStoresType() {
- return new StoresType();
+ public OptionType createOptionType() {
+ return new OptionType();
}
/**
- * Create an instance of {@link IdentityStoreMappingType }
+ * Create an instance of {@link ExternalConfigType }
*
*/
- public IdentityStoreMappingType createIdentityStoreMappingType() {
- return new IdentityStoreMappingType();
+ public ExternalConfigType createExternalConfigType() {
+ return new ExternalConfigType();
}
/**
@@ -193,38 +185,62 @@
}
/**
- * Create an instance of {@link OptionType }
+ * Create an instance of {@link RepositoryType }
*
*/
- public OptionType createOptionType() {
- return new OptionType();
+ public RepositoryType createRepositoryType() {
+ return new RepositoryType();
}
/**
- * Create an instance of {@link IdentityStoresType }
+ * Create an instance of {@link OptionsType }
*
*/
- public IdentityStoresType createIdentityStoresType() {
- return new IdentityStoresType();
+ public OptionsType createOptionsType() {
+ return new OptionsType();
}
/**
- * Create an instance of {@link GroupTypeMappingType }
+ * Create an instance of {@link SupportedIdentityObjectTypesType }
*
*/
- public GroupTypeMappingType createGroupTypeMappingType() {
- return new GroupTypeMappingType();
+ public SupportedIdentityObjectTypesType createSupportedIdentityObjectTypesType() {
+ return new SupportedIdentityObjectTypesType();
}
/**
- * Create an instance of {@link SupportedIdentityObjectTypesType }
+ * Create an instance of {@link IdentityTypeMappingsType }
*
*/
- public SupportedIdentityObjectTypesType createSupportedIdentityObjectTypesType() {
- return new SupportedIdentityObjectTypesType();
+ public IdentityTypeMappingsType createIdentityTypeMappingsType() {
+ return new IdentityTypeMappingsType();
}
/**
+ * Create an instance of {@link AttributesType }
+ *
+ */
+ public AttributesType createAttributesType() {
+ return new AttributesType();
+ }
+
+ /**
+ * Create an instance of {@link IdentityObjectTypeType.Credentials }
+ *
+ */
+ public IdentityObjectTypeType.Credentials createIdentityObjectTypeTypeCredentials() {
+ return new IdentityObjectTypeType.Credentials();
+ }
+
+ /**
+ * Create an instance of {@link RelationshipType }
+ *
+ */
+ public RelationshipType createRelationshipType() {
+ return new RelationshipType();
+ }
+
+ /**
* Create an instance of {@link JbossIdentityType }
*
*/
@@ -233,27 +249,27 @@
}
/**
- * Create an instance of {@link RealmType }
+ * Create an instance of {@link AttributeType }
*
*/
- public RealmType createRealmType() {
- return new RealmType();
+ public AttributeType createAttributeType() {
+ return new AttributeType();
}
/**
- * Create an instance of {@link IdentityStoreMappingsType }
+ * Create an instance of {@link IdentityObjectTypeType.Attributes }
*
*/
- public IdentityStoreMappingsType createIdentityStoreMappingsType() {
- return new IdentityStoreMappingsType();
+ public IdentityObjectTypeType.Attributes createIdentityObjectTypeTypeAttributes() {
+ return new IdentityObjectTypeType.Attributes();
}
/**
- * Create an instance of {@link RepositoryType }
+ * Create an instance of {@link RelationshipsType }
*
*/
- public RepositoryType createRepositoryType() {
- return new RepositoryType();
+ public RelationshipsType createRelationshipsType() {
+ return new RelationshipsType();
}
/**
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/OptionType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/OptionType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/OptionType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/OptionsType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/OptionsType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/OptionsType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RealmType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RealmType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RealmType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RealmsType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RealmsType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RealmsType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RelationshipType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RelationshipType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RelationshipType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RelationshipsType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RelationshipsType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RelationshipsType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RepositoriesType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RepositoriesType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RepositoriesType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RepositoryType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RepositoryType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/RepositoryType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/StoresType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/StoresType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/StoresType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/SupportedIdentityObjectTypesType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/SupportedIdentityObjectTypesType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/SupportedIdentityObjectTypesType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/SupportedRelationshipTypesType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/SupportedRelationshipTypesType.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/SupportedRelationshipTypesType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/package-info.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/package-info.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/jaxb2/generated/package-info.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -2,7 +2,7 @@
// This file was generated by the JavaTM Architecture for XML Binding(JAXB) Reference Implementation, vJAXB 2.1.3 in JDK
// See <a href="http://java.sun.com/xml/jaxb">http://java.sun.com/xml/jaxb</a>
// Any modifications to this file will be lost upon recompilation of the source schema.
-// Generated on: 2008.11.12 at 03:13:41 PM CET
+// Generated on: 2008.11.24 at 10:17:31 PM CET
//
@javax.xml.bind.annotation.XmlSchema(namespace = "urn:jboss:identity:config:v0_1", elementFormDefault = javax.xml.bind.annotation.XmlNsForm.QUALIFIED)
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/metadata/IdentityObjectTypeMetaDataImpl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/metadata/IdentityObjectTypeMetaDataImpl.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/configuration/metadata/IdentityObjectTypeMetaDataImpl.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -44,6 +44,8 @@
private Map<String, List<String>> options;
+ private List<String> credentials;
+
public IdentityObjectTypeMetaDataImpl()
{
}
@@ -78,6 +80,16 @@
this.attributes = attributes;
}
+ public List<String> getCredentials()
+ {
+ return credentials;
+ }
+
+ public void setCredentials(List<String> credentials)
+ {
+ this.credentials = credentials;
+ }
+
public Map<String, List<String>> getOptions()
{
return options;
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObject.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObject.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObject.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -29,6 +29,8 @@
import java.util.Collections;
import java.util.Arrays;
import java.util.List;
+import java.util.ArrayList;
+import java.util.LinkedList;
import javax.persistence.Column;
import javax.persistence.CascadeType;
@@ -43,9 +45,13 @@
import javax.persistence.JoinColumn;
import javax.persistence.NamedQueries;
import javax.persistence.NamedQuery;
+import javax.persistence.JoinTable;
import org.jboss.identity.exception.PolicyValidationException;
import org.jboss.identity.spi.model.IdentityObject;
+import org.jboss.identity.spi.credential.IdentityObjectCredentialType;
+import org.hibernate.annotations.Cascade;
+import org.hibernate.annotations.CollectionOfElements;
/**
* @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
@@ -58,17 +64,17 @@
),
@NamedQuery(
name = "findIdentityObjectsByType",
- query = "select o from HibernateIdentityObject o where o.realm like :realm and o.identityType.name like :typeName"
+ query = "select o from HibernateIdentityObject o where o.name like :nameFilter and o.realm like :realm and o.identityType.name like :typeName"
),
@NamedQuery(
name = "findIdentityObjectsByTypeOrderedByNameAsc",
- query = "select o from HibernateIdentityObject o where o.realm like :realm and o.identityType.name like :typeName " +
+ query = "select o from HibernateIdentityObject o where o.name like :nameFilter and o.realm like :realm and o.identityType.name like :typeName " +
"order by o.name asc"
),
@NamedQuery(
name = "findIdentityObjectsByTypeOrderedByNameDesc",
- query = "select o from HibernateIdentityObject o where o.realm like :realm and o.identityType.name like :typeName " +
- "order by o.name desc"
+ query = "select o from HibernateIdentityObject o where o.name like :nameFilter and o.realm like :realm and o.identityType.name like :typeName " +
+ "order by o.name desc"
),
@NamedQuery(
name = "countIdentityObjectsByType",
@@ -96,8 +102,21 @@
@OneToMany(mappedBy = "toIdentityObject")
private Set<HibernateIdentityObjectRelationship> toRelationships = new HashSet<HibernateIdentityObjectRelationship>();
+ @OneToMany(fetch = FetchType.EAGER, cascade = {CascadeType.PERSIST, CascadeType.MERGE, CascadeType.REMOVE},
+ mappedBy = "identityObject")
+ @org.hibernate.annotations.Cascade(
+ value = org.hibernate.annotations.CascadeType.DELETE_ORPHAN
+ )
+ private Set<HibernateIdentityObjectAttribute> attributes = new HashSet<HibernateIdentityObjectAttribute>();
+
+ @CollectionOfElements
+ @JoinTable(name = "identity_obj_properties", joinColumns = @JoinColumn(name = "IDENTITY_OBJ_ID"))
+ @Column(name = "PROPERTY")
+ private Map<String, String> properties = new HashMap<String, String>();
+
@OneToMany(fetch = FetchType.EAGER, cascade = {CascadeType.ALL})
- private Map<String, HibernateIdentityObjectAttribute> attributes = new HashMap<String, HibernateIdentityObjectAttribute>();
+ @Cascade(value = org.hibernate.annotations.CascadeType.DELETE_ORPHAN)
+ private Map<String, HibernateIdentityObjectCredential> credentials = new HashMap<String, HibernateIdentityObjectCredential>();
@ManyToOne(fetch = FetchType.EAGER)
@JoinColumn(nullable = false, unique = false, name="REALM")
@@ -149,20 +168,35 @@
return null;
}
+ public Set<HibernateIdentityObjectAttribute> getAttributes()
+ {
+ return attributes;
+ }
+
+ public void setAttributes(Set<HibernateIdentityObjectAttribute> attributes)
+ {
+ this.attributes = attributes;
+ }
+
public Set<String> getAttribute(String name)
{
- if (attributes.containsKey(name))
+ for (HibernateIdentityObjectAttribute attribute : attributes)
{
- return Collections.unmodifiableSet((attributes.get(name)).getValues());
+ if (attribute.getName().equals(name))
+ {
+ return Collections.unmodifiableSet(attribute.getValues());
+ }
}
+
+
return new HashSet<String>();
}
- public Map<String, String[]> getAttributes()
+ public Map<String, String[]> getAttributesAsMap()
{
Map<String, String[]> map = new HashMap<String, String[]>();
- for (HibernateIdentityObjectAttribute attribute : attributes.values())
+ for (HibernateIdentityObjectAttribute attribute : attributes)
{
Set<String> values = attribute.getValues();
map.put(attribute.getName(),values.toArray(new String[values.size()]));
@@ -171,48 +205,78 @@
return Collections.unmodifiableMap(map);
}
- public void setAttribute(String name, String[] values)
+ public void addAttribute(String name, String[] values)
{
-
- attributes.put(name, new HibernateIdentityObjectAttribute(name, values));
+ attributes.add(new HibernateIdentityObjectAttribute(this, name, values));
}
- public void setAttribute(String name, Set<String> values)
+ public void updateAttribute(String name, String[] values)
{
-
- attributes.put(name, new HibernateIdentityObjectAttribute(name, values));
+ for (HibernateIdentityObjectAttribute attribute : attributes)
+ {
+ if (attribute.getName().equals(name))
+ {
+ Set<String> v = new HashSet<String>();
+ for (String value : values)
+ {
+ v.add(value);
+ }
+ attribute.setValues(v);
+ break;
+ }
+ }
}
public void addAttributeValues(String name, String[] values)
{
- if (!attributes.containsKey(name))
+
+ for (HibernateIdentityObjectAttribute attribute : attributes)
{
- setAttribute(name, values);
+ if (attribute.getName().equals(name))
+ {
+ Set<String> mergedValues = new HashSet<String>(attribute.getValues());
+ List<String> list = Arrays.asList(values);
+ mergedValues.addAll(new HashSet<String>(list));
+ attribute.setValues(mergedValues);
+
+ return;
+ }
}
- else
- {
- Set<String> mergedValues = new HashSet<String>((attributes.get(name)).getValues());
- List<String> list = Arrays.asList(values);
- mergedValues.addAll(new HashSet<String>(list));
- setAttribute(name, mergedValues);
- }
+
+ addAttribute(name, values);
}
- public void setAttributes(Map<String, Set<String>> values)
+ public void updateAttributes(Map<String, Set<String>> values)
{
- Map<String, HibernateIdentityObjectAttribute> newAttrs= new HashMap<String, HibernateIdentityObjectAttribute>();
+ Set<HibernateIdentityObjectAttribute> newAttrs= new HashSet<HibernateIdentityObjectAttribute>();
for (String name : values.keySet())
{
-
- newAttrs.put(name, new HibernateIdentityObjectAttribute(name, new HashSet<String>(values.get(name))));
+ newAttrs.add(new HibernateIdentityObjectAttribute(this, name, new HashSet<String>(values.get(name))));
}
+
attributes = newAttrs;
}
+
+
public void removeAttribute(String name)
{
- attributes.remove(name);
+ HibernateIdentityObjectAttribute attributeToRemove = null;
+
+ for (HibernateIdentityObjectAttribute attribute : attributes)
+ {
+ if (attribute.getName().equals(name))
+ {
+ attributeToRemove = attribute;
+ break;
+ }
+ }
+
+ if (attributeToRemove != null)
+ {
+ attributes.remove(attributeToRemove);
+ }
}
public Set<HibernateIdentityObjectRelationship> getFromRelationships()
@@ -257,6 +321,50 @@
this.realm = realm;
}
+ public Map<String, HibernateIdentityObjectCredential> getCredentials()
+ {
+ return credentials;
+ }
+
+ public void setCredentials(Map<String, HibernateIdentityObjectCredential> credentials)
+ {
+ this.credentials = credentials;
+ }
+
+ public void addCredential(HibernateIdentityObjectCredential credential)
+ {
+ credential.setIdentityObject(this);
+ credentials.put(credential.getType().getName(), credential);
+ }
+
+ public boolean hasCredentials()
+ {
+ if (credentials != null && credentials.size() > 0)
+ {
+ return true;
+ }
+ return false;
+ }
+
+ public boolean hasCredential(IdentityObjectCredentialType type)
+ {
+ if (credentials != null && credentials.keySet().contains(type.getName()))
+ {
+ return true;
+ }
+ return false;
+ }
+
+ public Map<String, String> getProperties()
+ {
+ return properties;
+ }
+
+ public void setProperties(Map<String, String> properties)
+ {
+ this.properties = properties;
+ }
+
public void validatePolicy() throws PolicyValidationException
{
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectAttribute.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectAttribute.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectAttribute.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -31,6 +31,10 @@
import javax.persistence.Id;
import javax.persistence.GeneratedValue;
import javax.persistence.Embedded;
+import javax.persistence.Column;
+import javax.persistence.ManyToOne;
+import javax.persistence.JoinColumn;
+import javax.persistence.UniqueConstraint;
import java.util.Set;
import java.util.HashSet;
import java.util.List;
@@ -41,13 +45,18 @@
* @version : 0.1 $
*/
@Entity
-@Table(name = "identity_obj_attrs")
+@Table(name = "identity_obj_attrs", uniqueConstraints = {@UniqueConstraint(columnNames = {"NAME", "IDENTITY_OBJECT_ID"})})
public class HibernateIdentityObjectAttribute implements IdentityObjectAttribute
{
@Id
@GeneratedValue
private Long id;
+ @ManyToOne
+ @JoinColumn(name="IDENTITY_OBJECT_ID", nullable = false)
+ private HibernateIdentityObject identityObject;
+
+ @Column(name = "NAME")
private String name;
@CollectionOfElements
@@ -57,19 +66,22 @@
{
}
- public HibernateIdentityObjectAttribute(String name)
+ public HibernateIdentityObjectAttribute(HibernateIdentityObject identityObject, String name)
{
+ this.identityObject = identityObject;
this.name = name;
}
- public HibernateIdentityObjectAttribute(String name, Set<String> values)
+ public HibernateIdentityObjectAttribute(HibernateIdentityObject identityObject, String name, Set<String> values)
{
+ this.identityObject = identityObject;
this.name = name;
this.values = values;
}
- public HibernateIdentityObjectAttribute(String name, String[] values)
+ public HibernateIdentityObjectAttribute(HibernateIdentityObject identityObject, String name, String[] values)
{
+ this.identityObject = identityObject;
List<String> list = Arrays.asList(values);
this.name = name;
this.values = new HashSet<String>(list);
@@ -109,4 +121,15 @@
{
getValues().add(val);
}
+
+ public HibernateIdentityObject getIdentityObject()
+ {
+ return identityObject;
+ }
+
+ public void setIdentityObject(HibernateIdentityObject identityObject)
+ {
+ this.identityObject = identityObject;
+ }
+
}
Added: trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectCredential.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectCredential.java (rev 0)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectCredential.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -0,0 +1,152 @@
+/*
+* JBoss, a division of Red Hat
+* Copyright 2006, Red Hat Middleware, LLC, and individual contributors as indicated
+* by the @authors tag. See the copyright.txt in the distribution for a
+* full listing of individual contributors.
+*
+* This is free software; you can redistribute it and/or modify it
+* under the terms of the GNU Lesser General Public License as
+* published by the Free Software Foundation; either version 2.1 of
+* the License, or (at your option) any later version.
+*
+* This software is distributed in the hope that it will be useful,
+* but WITHOUT ANY WARRANTY; without even the implied warranty of
+* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+* Lesser General Public License for more details.
+*
+* You should have received a copy of the GNU Lesser General Public
+* License along with this software; if not, write to the Free
+* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
+* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
+*/
+
+package org.jboss.identity.impl.model.hibernate;
+
+import org.jboss.identity.spi.credential.IdentityObjectCredential;
+import org.hibernate.annotations.CollectionOfElements;
+
+import javax.persistence.Entity;
+import javax.persistence.Table;
+import javax.persistence.Id;
+import javax.persistence.GeneratedValue;
+import javax.persistence.Column;
+import javax.persistence.OneToMany;
+import javax.persistence.FetchType;
+import javax.persistence.CascadeType;
+import javax.persistence.JoinColumn;
+import javax.persistence.ManyToOne;
+import javax.persistence.JoinTable;
+import javax.persistence.UniqueConstraint;
+import java.util.Map;
+import java.util.HashMap;
+
+/**
+ * @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
+ * @version : 0.1 $
+ */
+@Entity
+@Table(name = "identity_obj_credential", uniqueConstraints = {@UniqueConstraint(columnNames = {"IDENTITY_TYPE", "IDENTITY_ID"})})
+public class HibernateIdentityObjectCredential implements IdentityObjectCredential
+{
+
+ @Id
+ @GeneratedValue
+ private Long id;
+
+ @ManyToOne(fetch = FetchType.EAGER)
+ @JoinColumn(name = "IDENTITY_TYPE", nullable = false)
+ private HibernateIdentityObjectCredentialType type;
+
+ @ManyToOne(fetch = FetchType.EAGER)
+ @JoinColumn(name = "IDENTITY_ID", nullable = false)
+ private HibernateIdentityObject identityObject;
+
+ @Column(name= "TEXT", nullable = true)
+ private String textValue;
+
+ @Column(name= "BINARY", nullable = true)
+ private byte[] binaryValue;
+
+ @CollectionOfElements
+ @JoinTable(name = "identity_obj_credential_properties", joinColumns = @JoinColumn(name = "CREDENTIAL_ID"))
+ @Column(name = "PROPERTY")
+ private Map<String, String> properties = new HashMap<String, String>();
+
+ public HibernateIdentityObjectCredential()
+ {
+ }
+
+ public Long getId()
+ {
+ return id;
+ }
+
+ public void setId(Long id)
+ {
+ this.id = id;
+ }
+
+ public String getTextValue()
+ {
+ return textValue;
+ }
+
+ public void setTextValue(String textValue)
+ {
+ this.textValue = textValue;
+ }
+
+ public byte[] getBinaryValue()
+ {
+ return binaryValue;
+ }
+
+ public void setBinaryValue(byte[] binaryValue)
+ {
+ this.binaryValue = binaryValue;
+ }
+
+ public Map<String, String> getProperties()
+ {
+ return properties;
+ }
+
+ public void setProperties(Map<String, String> properties)
+ {
+ this.properties = properties;
+ }
+
+ public HibernateIdentityObjectCredentialType getType()
+ {
+ return type;
+ }
+
+ public void setType(HibernateIdentityObjectCredentialType type)
+ {
+ this.type = type;
+ }
+
+ public HibernateIdentityObject getIdentityObject()
+ {
+ return identityObject;
+ }
+
+ public void setIdentityObject(HibernateIdentityObject identityObject)
+ {
+ this.identityObject = identityObject;
+ }
+
+ public Object getValue()
+ {
+ if (textValue != null)
+ {
+ return textValue;
+ }
+ return binaryValue;
+ }
+
+ public Object getEncodedValue()
+ {
+ return null;
+ }
+}
Added: trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectCredentialType.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectCredentialType.java (rev 0)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectCredentialType.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -0,0 +1,80 @@
+/*
+* JBoss, a division of Red Hat
+* Copyright 2006, Red Hat Middleware, LLC, and individual contributors as indicated
+* by the @authors tag. See the copyright.txt in the distribution for a
+* full listing of individual contributors.
+*
+* This is free software; you can redistribute it and/or modify it
+* under the terms of the GNU Lesser General Public License as
+* published by the Free Software Foundation; either version 2.1 of
+* the License, or (at your option) any later version.
+*
+* This software is distributed in the hope that it will be useful,
+* but WITHOUT ANY WARRANTY; without even the implied warranty of
+* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+* Lesser General Public License for more details.
+*
+* You should have received a copy of the GNU Lesser General Public
+* License along with this software; if not, write to the Free
+* Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
+* 02110-1301 USA, or see the FSF site: http://www.fsf.org.
+*/
+
+package org.jboss.identity.impl.model.hibernate;
+
+import org.jboss.identity.spi.credential.IdentityObjectCredential;
+import org.jboss.identity.spi.credential.IdentityObjectCredentialType;
+
+import javax.persistence.Entity;
+import javax.persistence.Table;
+import javax.persistence.Id;
+import javax.persistence.GeneratedValue;
+import javax.persistence.Column;
+
+/**
+ * @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
+ * @version : 0.1 $
+ */
+@Entity
+@Table(name = "identity_obj_credential_type")
+public class HibernateIdentityObjectCredentialType implements IdentityObjectCredentialType
+{
+
+ @Id
+ @GeneratedValue
+ private Long id;
+
+ @Column(name = "NAME", unique = true)
+ private String name;
+
+ public HibernateIdentityObjectCredentialType()
+ {
+ }
+
+ public HibernateIdentityObjectCredentialType(String typeName)
+ {
+ this.name = typeName;
+ }
+
+ public Long getId()
+ {
+ return id;
+ }
+
+ public void setId(Long id)
+ {
+ this.id = id;
+ }
+
+ public String getName()
+ {
+ return name;
+ }
+
+ public void setName(String name)
+ {
+ this.name = name;
+ }
+
+
+}
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectRelationshipName.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectRelationshipName.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateIdentityObjectRelationshipName.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -46,16 +46,16 @@
),
@NamedQuery(
name = "findIdentityObjectRelationshipNames",
- query = "select rn.name from HibernateIdentityObjectRelationshipName rn where rn.realm like :realm"
+ query = "select rn.name from HibernateIdentityObjectRelationshipName rn where rn.name like :nameFilter and rn.realm like :realm"
),
@NamedQuery(
name = "findIdentityObjectRelationshipNamesOrderedByNameAsc",
- query = "select rn.name from HibernateIdentityObjectRelationshipName rn where rn.realm like :realm " +
+ query = "select rn.name from HibernateIdentityObjectRelationshipName rn where rn.name like :nameFilter and rn.realm like :realm " +
"order by rn.name asc"
),
@NamedQuery(
name = "findIdentityObjectRelationshipNamesOrderedByNameDesc",
- query = "select rn.name from HibernateIdentityObjectRelationshipName rn where rn.realm like :realm " +
+ query = "select rn.name from HibernateIdentityObjectRelationshipName rn where rn.name like :nameFilter and rn.realm like :realm " +
"order by rn.name desc"
),
@NamedQuery(
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateRealm.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateRealm.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/model/hibernate/HibernateRealm.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -22,6 +22,8 @@
package org.jboss.identity.impl.model.hibernate;
+import org.hibernate.annotations.CollectionOfElements;
+
import javax.persistence.Entity;
import javax.persistence.Table;
import javax.persistence.UniqueConstraint;
@@ -33,6 +35,8 @@
import javax.persistence.CascadeType;
import javax.persistence.NamedQueries;
import javax.persistence.NamedQuery;
+import javax.persistence.JoinTable;
+import javax.persistence.JoinColumn;
import java.util.Map;
import java.util.HashMap;
import java.util.Set;
@@ -63,9 +67,11 @@
@Column(name = "NAME", nullable = false)
private String name;
- @OneToMany(fetch = FetchType.EAGER, cascade = {CascadeType.ALL})
- private Map<String, HibernateIdentityObjectAttribute> attributes = new HashMap<String, HibernateIdentityObjectAttribute>();
-
+ @CollectionOfElements
+ @JoinTable(name = "identity_realm_properties", joinColumns = @JoinColumn(name = "REALM_ID"))
+ @Column(name = "PROPERTY")
+ private Map<String, String> properties = new HashMap<String, String>();
+
public HibernateRealm()
{
}
@@ -95,70 +101,13 @@
this.name = name;
}
- public Set<String> getAttribute(String name) {
- if (attributes.containsKey(name))
- {
- return Collections.unmodifiableSet((attributes.get(name)).getValues());
- }
- return new HashSet<String>();
- }
-
- public Map<String, String[]> getAttributes()
+ public Map<String, String> getProperties()
{
- Map<String, String[]> map = new HashMap<String, String[]>();
-
- for (HibernateIdentityObjectAttribute attribute : attributes.values())
- {
- Set<String> values = attribute.getValues();
- map.put(attribute.getName(),values.toArray(new String[values.size()]));
- }
-
- return Collections.unmodifiableMap(map);
+ return properties;
}
- public void setAttribute(String name, String[] values)
+ public void setProperties(Map<String, String> properties)
{
-
- attributes.put(name, new HibernateIdentityObjectAttribute(name, values));
+ this.properties = properties;
}
-
- public void setAttribute(String name, Set<String> values)
- {
-
- attributes.put(name, new HibernateIdentityObjectAttribute(name, values));
- }
-
- public void addAttributeValues(String name, String[] values)
- {
- if (!attributes.containsKey(name))
- {
- setAttribute(name, values);
- }
- else
- {
- Set<String> mergedValues = new HashSet<String>((attributes.get(name)).getValues());
- List<String> list = Arrays.asList(values);
- mergedValues.addAll(new HashSet<String>(list));
- setAttribute(name, mergedValues);
- }
- }
-
- public void setAttributes(Map<String, Set<String>> values)
- {
- Map<String, HibernateIdentityObjectAttribute> newAttrs= new HashMap<String, HibernateIdentityObjectAttribute>();
-
- for (String name : values.keySet())
- {
-
- newAttrs.put(name, new HibernateIdentityObjectAttribute(name, new HashSet<String>(values.get(name))));
- }
- attributes = newAttrs;
- }
-
- public void removeAttribute(String name)
- {
- attributes.remove(name);
- }
-
-
}
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/repository/WrapperIdentityStoreRepository.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/repository/WrapperIdentityStoreRepository.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/repository/WrapperIdentityStoreRepository.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -22,24 +22,6 @@
package org.jboss.identity.impl.repository;
-import org.jboss.identity.spi.store.IdentityStore;
-import org.jboss.identity.spi.store.AttributeStore;
-import org.jboss.identity.spi.store.FeaturesMetaData;
-import org.jboss.identity.spi.store.IdentityStoreInvocationContext;
-import org.jboss.identity.spi.store.IdentityStoreSession;
-import org.jboss.identity.spi.model.IdentityObject;
-import org.jboss.identity.spi.model.IdentityObjectType;
-import org.jboss.identity.spi.model.IdentityObjectRelationshipType;
-import org.jboss.identity.spi.model.IdentityObjectRelationship;
-import org.jboss.identity.spi.exception.OperationNotSupportedException;
-import org.jboss.identity.spi.configuration.metadata.IdentityStoreConfigurationMetaData;
-import org.jboss.identity.exception.IdentityException;
-
-import java.util.Map;
-import java.util.Collection;
-import java.util.Set;
-import java.io.IOException;
-
/**
* Simply wraps IdentityStore and AttributeStore and delegates all the calls
*
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/FeaturesMetaDataImpl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/FeaturesMetaDataImpl.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/FeaturesMetaDataImpl.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -54,23 +54,33 @@
private Map<String, Map<String, Set<String>>> supportedRelationshipMappings = new HashMap<String, Map<String, Set<String>>>();
-
+
public FeaturesMetaDataImpl(IdentityStoreConfigurationMetaData configurationMD,
- Set<Class> supportedControls,
- Map<String, Set<String>> supportedCredentials)
+ Set<Class> supportedControls)
{
+ Map<String, Set<String>> supportedCredentials = new HashMap<String, Set<String>>();
+
for (IdentityObjectTypeMetaData typeMetaData : configurationMD.getSupportedIdentityTypes())
{
supportedTypeNames.add(typeMetaData.getName());
+
+ if (typeMetaData.getCredentials() != null)
+ {
+ Set<String> credentials = new HashSet<String>(typeMetaData.getCredentials());
+ supportedCredentials.put(typeMetaData.getName(), credentials);
+ }
+
}
supportedTypeNames = Collections.unmodifiableSet(supportedTypeNames);
+ this.supportedCredentials = Collections.unmodifiableMap(supportedCredentials);
+
this.supportedSearchControls = Collections.unmodifiableSet(supportedControls);
- this.supportedCredentials = Collections.unmodifiableMap(supportedCredentials);
+
// Supported relationships
List<String> relationshipNames = configurationMD.getSupportedRelationshipTypes();
@@ -78,7 +88,7 @@
for (IdentityObjectTypeMetaData identityObjectTypeMetaData : configurationMD.getSupportedIdentityTypes())
{
String fromTypeName = identityObjectTypeMetaData.getName();
-
+
if (identityObjectTypeMetaData.getRelationships() == null)
{
continue;
@@ -122,10 +132,14 @@
}
}
+
+
}
+
+
}
public boolean isControlSupported(IdentityObjectType identityObjectType, IdentityObjectSearchControl control)
@@ -181,7 +195,7 @@
public boolean isCredentialSupported(IdentityObjectType identityObjectType, IdentityObjectCredentialType credentialType)
{
Set<String> types = supportedCredentials.get(identityObjectType.getName());
- if (types != null && types.contains(credentialType))
+ if (types != null && types.contains(credentialType.getName()))
{
return true;
}
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/hibernate/HibernateIdentityStoreImpl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/hibernate/HibernateIdentityStoreImpl.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/hibernate/HibernateIdentityStoreImpl.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -35,6 +35,8 @@
import org.jboss.identity.spi.configuration.metadata.IdentityStoreConfigurationMetaData;
import org.jboss.identity.spi.configuration.metadata.IdentityObjectTypeMetaData;
import org.jboss.identity.spi.credential.IdentityObjectCredential;
+import org.jboss.identity.spi.credential.IdentityObjectCredentialType;
+import org.jboss.identity.spi.attribute.AttributeMetaData;
import org.jboss.identity.exception.IdentityException;
import org.jboss.identity.impl.model.hibernate.HibernateIdentityObject;
import org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectRelationship;
@@ -42,9 +44,12 @@
import org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectType;
import org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectRelationshipName;
import org.jboss.identity.impl.model.hibernate.HibernateRealm;
-import org.jboss.identity.impl.NotYetImplementedException;
+import org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectCredentialType;
+import org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectCredential;
import org.jboss.identity.impl.api.PageSearchControl;
import org.jboss.identity.impl.api.SortByNameSearchControl;
+import org.jboss.identity.impl.api.AttributeFilterSearchControl;
+import org.jboss.identity.impl.api.NameFilterSearchControl;
import org.jboss.identity.impl.store.FeaturesMetaDataImpl;
import org.hibernate.ejb.HibernateEntityManager;
import org.hibernate.ejb.HibernateEntityManagerFactory;
@@ -61,7 +66,9 @@
import java.util.Iterator;
import java.util.HashSet;
import java.util.LinkedList;
+import java.util.Arrays;
import java.util.HashMap;
+import java.util.Collections;
/**
* @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
@@ -97,8 +104,14 @@
public static final String IS_REALM_AWARE = "isRealmAware";
+ public static final String ALLOW_NOT_DEFINED_ATTRIBUTES = "allowNotDefinedAttributes";
+
public static final String DEFAULT_REALM_NAME = HibernateIdentityStoreImpl.class.getName() + ".DEFAULT_REALM";
+ public static final String CREDENTIAL_TYPE_PASSWORD = "PASSWORD";
+
+ public static final String CREDENTIAL_TYPE_BINARY = "BINARY";
+
private String id;
private FeaturesMetaData supportedFeatures;
@@ -107,19 +120,36 @@
private boolean isRealmAware = false;
+ private boolean isAllowNotDefinedAttributes = false;
+
// TODO: rewrite this into some more handy object
private IdentityStoreConfigurationMetaData configurationMD;
- private static Set<Class> supportedSearchControls = new HashSet<Class>();
+ private static Set<Class> supportedIdentityObjectSearchControls = new HashSet<Class>();
+ private static Set<String> supportedCredentialTypes = new HashSet<String>();
+
+ // <IdentityObjectType name, Set<Attribute name>>
+ private Map<String, Set<String>> attributeMappings = new HashMap<String, Set<String>>();
+
+ // <IdentityObjectType name, <Attribute name, MD>
+ private Map<String, Map<String, AttributeMetaData>> attributesMetaData = new HashMap<String, Map<String, AttributeMetaData>>();
+
+ // <IdentityObjectType name, <Attribute store mapping, Attribute name>
+ private Map<String, Map<String, String>> reverseAttributeMappings = new HashMap<String, Map<String, String>>();
+
static {
// List all supported controls classes
- //TODO: attributefilter?
+ supportedIdentityObjectSearchControls.add(PageSearchControl.class);
+ supportedIdentityObjectSearchControls.add(SortByNameSearchControl.class);
+ supportedIdentityObjectSearchControls.add(AttributeFilterSearchControl.class);
+ supportedIdentityObjectSearchControls.add(NameFilterSearchControl.class);
- supportedSearchControls.add(PageSearchControl.class);
- supportedSearchControls.add(SortByNameSearchControl.class);
-
+ // credential types supported by this impl
+ supportedCredentialTypes.add(CREDENTIAL_TYPE_PASSWORD);
+ supportedCredentialTypes.add(CREDENTIAL_TYPE_BINARY);
+
}
public HibernateIdentityStoreImpl(String id)
@@ -131,22 +161,43 @@
{
this.configurationMD = configurationMD;
- supportedFeatures = new FeaturesMetaDataImpl(configurationMD, supportedSearchControls, new HashMap<String, Set<String>>());
+ id = configurationMD.getId();
+ supportedFeatures = new FeaturesMetaDataImpl(configurationMD, supportedIdentityObjectSearchControls);
+
String persistenceUnit = configurationMD.getOptionSingleValue(PERSISTENCE_UNIT);
- if (persistenceUnit == null)
+ String populateMembershipTypes = configurationMD.getOptionSingleValue(POPULATE_MEMBERSHIP_TYPES);
+ String populateIdentityObjectTypes = configurationMD.getOptionSingleValue(POPULATE_IDENTITY_OBJECT_TYPES);
+
+ HibernateEntityManager em = bootstrapHibernateEntityManager(persistenceUnit);
+
+ // Attribute mappings - helper structures
+
+ for (IdentityObjectTypeMetaData identityObjectTypeMetaData : configurationMD.getSupportedIdentityTypes())
{
- throw new IdentityException("Persistence Unit not defined for IdentityStore: " + getId());
- }
+ Set<String> names = new HashSet<String>();
+ Map<String, AttributeMetaData> metadataMap = new HashMap<String, AttributeMetaData>();
+ Map<String, String> reverseMap = new HashMap<String, String>();
+ for (AttributeMetaData attributeMetaData : identityObjectTypeMetaData.getAttributes())
+ {
+ names.add(attributeMetaData.getName());
+ metadataMap.put(attributeMetaData.getName(), attributeMetaData);
+ if (attributeMetaData.getStoreMapping() != null)
+ {
+ reverseMap.put(attributeMetaData.getStoreMapping(), attributeMetaData.getName());
+ }
+ }
- emFactory = (HibernateEntityManagerFactory)Persistence.createEntityManagerFactory(persistenceUnit);
+ // Use unmodifiableSet as it'll be exposed directly
+ attributeMappings.put(identityObjectTypeMetaData.getName(), Collections.unmodifiableSet(names));
- String populateMembershipTypes = configurationMD.getOptionSingleValue(POPULATE_MEMBERSHIP_TYPES);
- String populateIdentityObjectTypes = configurationMD.getOptionSingleValue(POPULATE_IDENTITY_OBJECT_TYPES);
+ attributesMetaData.put(identityObjectTypeMetaData.getName(), metadataMap);
- HibernateEntityManager em = (HibernateEntityManager)emFactory.createEntityManager();
+ reverseAttributeMappings.put(identityObjectTypeMetaData.getName(), reverseMap);
+ }
+ attributeMappings = Collections.unmodifiableMap(attributeMappings);
if (populateMembershipTypes != null && populateMembershipTypes.equalsIgnoreCase("true"))
{
@@ -189,6 +240,18 @@
}
+ if (supportedCredentialTypes != null && supportedCredentialTypes.size() > 0)
+ {
+ try
+ {
+ populateCredentialTypes(em, supportedCredentialTypes.toArray(new String[supportedCredentialTypes.size()]));
+ }
+ catch (Exception e)
+ {
+ throw new IdentityException("Failed to populated credential types");
+ }
+ }
+
String realmAware = configurationMD.getOptionSingleValue(IS_REALM_AWARE);
if (realmAware != null && realmAware.equalsIgnoreCase("true"))
@@ -196,6 +259,13 @@
this.isRealmAware = true;
}
+ String allowNotDefineAttributes = configurationMD.getOptionSingleValue(ALLOW_NOT_DEFINED_ATTRIBUTES);
+
+ if (allowNotDefineAttributes != null && allowNotDefineAttributes.equalsIgnoreCase("true"))
+ {
+ this.isAllowNotDefinedAttributes = true;
+ }
+
// Default realm
HibernateRealm realm = null;
@@ -220,10 +290,24 @@
{
addRealm(em, DEFAULT_REALM_NAME);
}
-
+
}
+ // this is separate method to allow easier testing
+ protected HibernateEntityManager bootstrapHibernateEntityManager(String persistenceUnit) throws IdentityException
+ {
+ if (persistenceUnit == null)
+ {
+ throw new IdentityException("Persistence Unit not defined for IdentityStore: " + getId());
+ }
+ emFactory = (HibernateEntityManagerFactory)Persistence.createEntityManagerFactory(persistenceUnit);
+
+ return (HibernateEntityManager)emFactory.createEntityManager();
+
+ }
+
+
public IdentityStoreSession createIdentityStoreSession() throws IdentityException
{
try
@@ -277,7 +361,8 @@
List results = em.createNamedQuery("findIdentityObjectByNameAndType")
.setParameter("realm", realm)
.setParameter("name", name)
- .setParameter("typeName", identityObjectType.getName()).getResultList();
+ .setParameter("typeName", identityObjectType.getName())
+ .getResultList();
if (results.size() != 0)
{
@@ -294,7 +379,7 @@
{
for (Map.Entry<String, String[]> entry : attributes.entrySet())
{
- io.setAttribute(entry.getKey(), entry.getValue());
+ io.addAttribute(entry.getKey(), entry.getValue());
}
}
@@ -315,11 +400,28 @@
{
HibernateIdentityObject hibernateObject = safeGet(ctx, identity);
- //TODO: handle cleanup of present relationships
+ HibernateEntityManager hem = getHibernateEntityManager(ctx);
try
{
- getHibernateEntityManager(ctx).remove(hibernateObject);
+ // Remove all related relationships
+ for (HibernateIdentityObjectRelationship relationship : hibernateObject.getFromRelationships())
+ {
+ relationship.getFromIdentityObject().getFromRelationships().remove(relationship);
+ relationship.getToIdentityObject().getToRelationships().remove(relationship);
+
+ hem.remove(relationship);
+ }
+
+ for (HibernateIdentityObjectRelationship relationship : hibernateObject.getToRelationships())
+ {
+ relationship.getFromIdentityObject().getFromRelationships().remove(relationship);
+ relationship.getToIdentityObject().getToRelationships().remove(relationship);
+
+ hem.remove(relationship);
+ }
+
+ hem.remove(hibernateObject);
}
catch (Exception e)
{
@@ -392,7 +494,7 @@
throw new IllegalArgumentException("id is null");
}
- HibernateIdentityObject hibernateObject = null;
+ HibernateIdentityObject hibernateObject;
try
{
@@ -418,6 +520,8 @@
PageSearchControl pageSearchControl = null;
SortByNameSearchControl sortSearchControl = null;
+ AttributeFilterSearchControl attributeFilterControl = null;
+ NameFilterSearchControl nameFilterSearchControl = null;
if (controls != null)
{
@@ -431,6 +535,14 @@
{
sortSearchControl = (SortByNameSearchControl)control;
}
+ else if (control instanceof AttributeFilterSearchControl)
+ {
+ attributeFilterControl = (AttributeFilterSearchControl)control;
+ }
+ else if (control instanceof NameFilterSearchControl)
+ {
+ nameFilterSearchControl = (NameFilterSearchControl)control;
+ }
}
}
@@ -461,19 +573,30 @@
q = em.createNamedQuery("findIdentityObjectsByType");
}
-
- q.setParameter("realm", getRealm(em, ctx))
- .setParameter("typeName", hibernateType.getName());
-
if (pageSearchControl != null)
{
- q.setFirstResult(pageSearchControl.getOffset());
if (pageSearchControl.getLimit() > 0)
{
q.setMaxResults(pageSearchControl.getLimit());
}
+ q.setFirstResult(pageSearchControl.getOffset());
+
}
+ q.setParameter("realm", getRealm(em, ctx))
+ .setParameter("typeName", hibernateType.getName());
+
+ if (nameFilterSearchControl != null)
+ {
+ q.setParameter("nameFilter", nameFilterSearchControl.getFilter().replaceAll("\\*", "%"));
+ }
+ else
+ {
+ q.setParameter("nameFilter", "%");
+ }
+
+
+
results = (List<IdentityObject>)q.getResultList();
}
@@ -482,10 +605,16 @@
throw new IdentityException("Cannot find IdentityObjects with type '" + identityType.getName() + "'", e);
}
+ if (attributeFilterControl != null)
+ {
+ filterByAttributesValues(results, attributeFilterControl.getValues());
+ }
+
return results;
}
+
public Collection<IdentityObject> findIdentityObject(IdentityStoreInvocationContext ctx, IdentityObjectType identityType) throws IdentityException
{
return findIdentityObject(ctx, identityType, null);
@@ -498,10 +627,14 @@
HibernateIdentityObject hibernateObject = safeGet(ctx, identity);
- List<IdentityObject> results = null;
+ List<IdentityObject> results;
+ checkControls(controls);
+
PageSearchControl pageSearchControl = null;
SortByNameSearchControl sortSearchControl = null;
+ AttributeFilterSearchControl attributeFilterControl = null;
+ NameFilterSearchControl nameFilterSearchControl = null;
if (controls != null)
{
@@ -515,6 +648,14 @@
{
sortSearchControl = (SortByNameSearchControl)control;
}
+ else if (control instanceof AttributeFilterSearchControl)
+ {
+ attributeFilterControl = (AttributeFilterSearchControl)control;
+ }
+ else if (control instanceof NameFilterSearchControl)
+ {
+ nameFilterSearchControl = (NameFilterSearchControl)control;
+ }
}
}
@@ -544,7 +685,8 @@
if (parent)
{
- hqlString.append("select ior.toIdentityObject from HibernateIdentityObjectRelationship ior where ior.type.name like :relType and ior.fromIdentityObject like :identity");
+ hqlString.append("select ior.toIdentityObject from HibernateIdentityObjectRelationship ior where " +
+ "ior.toIdentityObject.name like :nameFilter and ior.type.name like :relType and ior.fromIdentityObject like :identity");
if (orderByName)
{
@@ -557,7 +699,8 @@
}
else
{
- hqlString.append("select ior.fromIdentityObject from HibernateIdentityObjectRelationship ior where ior.type.name like :relType and ior.toIdentityObject like :identity");
+ hqlString.append("select ior.fromIdentityObject from HibernateIdentityObjectRelationship ior where " +
+ "ior.fromIdentityObject.name like :nameFilter and ior.type.name like :relType and ior.toIdentityObject like :identity");
if (orderByName)
@@ -570,9 +713,21 @@
}
}
+
+
q = getHibernateEntityManager(ctx).getSession().createQuery(hqlString.toString())
.setParameter("relType", relationshipType.getName())
.setParameter("identity",hibernateObject);
+
+ if (nameFilterSearchControl != null)
+ {
+ q.setParameter("nameFilter", nameFilterSearchControl.getFilter().replaceAll("\\*", "%"));
+ }
+ else
+ {
+ q.setParameter("nameFilter", "%");
+ }
+
if (pageSearchControl != null)
{
@@ -583,6 +738,8 @@
}
}
+
+
results = q.list();
@@ -592,20 +749,29 @@
throw new IdentityException("Cannot find IdentityObjects", e);
}
+ if (attributeFilterControl != null)
+ {
+ filterByAttributesValues(results, attributeFilterControl.getValues());
+ }
+
return results;
}
- public Collection<IdentityObject> findIdentityObject(IdentityStoreInvocationContext ctx, IdentityObject identity, IdentityObjectRelationshipType relationshipType, boolean parent) throws IdentityException
+ public Collection<IdentityObject> findIdentityObject(IdentityStoreInvocationContext ctx,
+ IdentityObject identity,
+ IdentityObjectRelationshipType relationshipType,
+ boolean parent) throws IdentityException
{
return findIdentityObject(ctx, identity, relationshipType, parent, null);
}
- public IdentityObjectRelationship createRelationship(IdentityStoreInvocationContext ctx, IdentityObject fromIdentity, IdentityObject toIdentity,
- IdentityObjectRelationshipType relationshipType,
- String name, boolean createNames) throws IdentityException
+ public IdentityObjectRelationship createRelationship(IdentityStoreInvocationContext ctx,
+ IdentityObject fromIdentity,
+ IdentityObject toIdentity,
+ IdentityObjectRelationshipType relationshipType,
+ String name, boolean createNames) throws IdentityException
{
- //TODO: check name
if (relationshipType == null)
{
@@ -639,6 +805,11 @@
HibernateIdentityObjectRelationshipName relationshipName = (HibernateIdentityObjectRelationshipName)getHibernateEntityManager(ctx).getSession().createCriteria(HibernateIdentityObjectRelationshipName.class).add(Restrictions.eq("name", name)).uniqueResult();
+ if (relationshipName == null)
+ {
+ throw new IdentityException("Relationship name not present in the store");
+ }
+
relationship = new HibernateIdentityObjectRelationship(type, fromIO, toIO, relationshipName);
}
else
@@ -652,9 +823,10 @@
}
+
+
public void removeRelationship(IdentityStoreInvocationContext ctx, IdentityObject fromIdentity, IdentityObject toIdentity, IdentityObjectRelationshipType relationshipType, String name) throws IdentityException
{
- //TODO: check name
if (relationshipType == null)
{
@@ -678,6 +850,13 @@
}
else
{
+ HibernateIdentityObjectRelationshipName relationshipName = (HibernateIdentityObjectRelationshipName)getHibernateEntityManager(ctx).getSession().createCriteria(HibernateIdentityObjectRelationshipName.class).add(Restrictions.eq("name", name)).uniqueResult();
+
+ if (relationshipName == null)
+ {
+ throw new IdentityException("Relationship name not present in the store");
+ }
+
query = getHibernateEntityManager(ctx).getSession().createQuery(QUERY_RELATIONSHIP_BY_FROM_TO_TYPE_NAME)
.setParameter("fromIO", fromIO)
.setParameter("toIO", toIO)
@@ -701,12 +880,8 @@
}
-
-
public void removeRelationships(IdentityStoreInvocationContext ctx, IdentityObject identity1, IdentityObject identity2, boolean named) throws IdentityException
{
- //TODO: named
-
HibernateIdentityObject hio1 = safeGet(ctx, identity1);
HibernateIdentityObject hio2 = safeGet(ctx, identity2);
@@ -719,9 +894,14 @@
for (Iterator iterator = results.iterator(); iterator.hasNext();)
{
HibernateIdentityObjectRelationship relationship = (HibernateIdentityObjectRelationship) iterator.next();
- relationship.getFromIdentityObject().getFromRelationships().remove(relationship);
- relationship.getToIdentityObject().getToRelationships().remove(relationship);
- getHibernateEntityManager(ctx).remove(relationship);
+
+ if ((named && relationship.getName() != null) ||
+ (!named && relationship.getName() == null))
+ {
+ relationship.getFromIdentityObject().getFromRelationships().remove(relationship);
+ relationship.getToIdentityObject().getToRelationships().remove(relationship);
+ getHibernateEntityManager(ctx).remove(relationship);
+ }
}
}
@@ -813,8 +993,12 @@
HibernateEntityManager em = getHibernateEntityManager(ctx);
+ checkControls(controls);
+
PageSearchControl pageSearchControl = null;
SortByNameSearchControl sortSearchControl = null;
+ AttributeFilterSearchControl attributeFilterControl = null;
+ NameFilterSearchControl nameFilterSearchControl = null;
if (controls != null)
{
@@ -828,6 +1012,14 @@
{
sortSearchControl = (SortByNameSearchControl)control;
}
+ else if (control instanceof AttributeFilterSearchControl)
+ {
+ attributeFilterControl = (AttributeFilterSearchControl)control;
+ }
+ else if (control instanceof NameFilterSearchControl)
+ {
+ nameFilterSearchControl = (NameFilterSearchControl)control;
+ }
}
}
@@ -854,6 +1046,16 @@
q.setParameter("realm", getRealm(em, ctx));
+ if (nameFilterSearchControl != null)
+ {
+ q.setParameter("nameFilter", nameFilterSearchControl.getFilter().replaceAll("\\*", "%"));
+ }
+ else
+ {
+ q.setParameter("nameFilter", "%");
+ }
+
+
if (pageSearchControl != null)
{
q.setFirstResult(pageSearchControl.getOffset());
@@ -890,6 +1092,8 @@
HibernateEntityManager em = getHibernateEntityManager(ctx);
+ checkControls(controls);
+
PageSearchControl pageSearchControl = null;
SortByNameSearchControl sortSearchControl = null;
@@ -961,8 +1165,15 @@
public <T extends IdentityObjectType> Set<String> getSupportedAttributeNames(IdentityStoreInvocationContext ctx, T identityType) throws IdentityException
{
- //TODO: NYI
- throw new NotYetImplementedException();
+ checkIOType(identityType);
+
+ if (attributeMappings.containsKey(identityType.getName()))
+ {
+ return attributeMappings.get(identityType.getName());
+ }
+
+ return new HashSet<String>();
+
}
public Map<String, String[]> getAttributes(IdentityStoreInvocationContext ctx, IdentityObject identity) throws IdentityException
@@ -970,8 +1181,21 @@
HibernateIdentityObject hibernateObject = safeGet(ctx, identity);
- return hibernateObject.getAttributes();
+ Map<String, String[]> storeAttributes = hibernateObject.getAttributesAsMap();
+ Map<String, String[]> result = new HashMap<String, String[]>();
+
+ // Remap the names
+ for (Map.Entry<String, String[]> entry : storeAttributes.entrySet())
+ {
+ String name = resolveAttributeNameFromStoreMapping(identity.getIdentityType(), entry.getKey());
+ if (name != null)
+ {
+ result.put(name, entry.getValue());
+ }
+ }
+ return result;
+
}
public void updateAttributes(IdentityStoreInvocationContext ctx, IdentityObject identity, Map<String, String[]> attributes) throws IdentityException
@@ -982,11 +1206,30 @@
throw new IllegalArgumentException("attributes are null");
}
+ Map<String, String[]> mappedAttributes = new HashMap<String, String[]>();
+
+ for (Map.Entry<String, String[]> entry : attributes.entrySet())
+ {
+ String name = resolveAttributeStoreMapping(identity.getIdentityType(), entry.getKey());
+ mappedAttributes.put(name, entry.getValue());
+
+ Map<String, AttributeMetaData> mdMap = attributesMetaData.get(identity.getIdentityType().getName());
+
+ if (mdMap != null)
+ {
+ AttributeMetaData amd = mdMap.get(entry.getKey());
+ if (amd != null && !amd.isMultivalued() && entry.getValue().length > 1)
+ {
+ throw new IdentityException("Cannot assigned multiply values to single valued attribute: " + entry.getKey());
+ }
+ }
+ }
+
HibernateIdentityObject hibernateObject = safeGet(ctx, identity);
- for (String name : attributes.keySet())
+ for (String name : mappedAttributes.keySet())
{
- hibernateObject.setAttribute(name, attributes.get(name));
+ hibernateObject.updateAttribute(name, mappedAttributes.get(name));
}
}
@@ -999,11 +1242,30 @@
throw new IllegalArgumentException("attributes are null");
}
+ Map<String, String[]> mappedAttributes = new HashMap<String, String[]>();
+
+ for (Map.Entry<String, String[]> entry : attributes.entrySet())
+ {
+ String name = resolveAttributeStoreMapping(identity.getIdentityType(), entry.getKey());
+ mappedAttributes.put(name, entry.getValue());
+
+ Map<String, AttributeMetaData> mdMap = attributesMetaData.get(identity.getIdentityType().getName());
+
+ if (mdMap != null)
+ {
+ AttributeMetaData amd = mdMap.get(entry.getKey());
+ if (amd != null && !amd.isMultivalued() && entry.getValue().length > 1)
+ {
+ throw new IdentityException("Cannot assigned multiply values to single valued attribute: " + entry.getKey());
+ }
+ }
+ }
+
HibernateIdentityObject hibernateObject = safeGet(ctx, identity);
- for (String name : attributes.keySet())
+ for (String name : mappedAttributes.keySet())
{
- hibernateObject.addAttributeValues(name, attributes.get(name));
+ hibernateObject.addAttributeValues(name, mappedAttributes.get(name));
}
}
@@ -1015,9 +1277,29 @@
throw new IllegalArgumentException("attributes are null");
}
+ String[] mappedAttributes = new String[attributes.length];
+
+ for (int i = 0; i < attributes.length; i++)
+ {
+ String name = resolveAttributeStoreMapping(identity.getIdentityType(), attributes[i]);
+ mappedAttributes[i] = name;
+
+ Map<String, AttributeMetaData> mdMap = attributesMetaData.get(identity.getIdentityType().getName());
+
+ if (mdMap != null)
+ {
+ AttributeMetaData amd = mdMap.get(attributes[i]);
+ if (amd != null && amd.isRequired())
+ {
+ throw new IdentityException("Cannot remove required attribute: " + attributes[i]);
+ }
+ }
+
+ }
+
HibernateIdentityObject hibernateObject = safeGet(ctx, identity);
- for (String attr : attributes)
+ for (String attr : mappedAttributes)
{
hibernateObject.removeAttribute(attr);
}
@@ -1025,16 +1307,123 @@
public boolean validateCredential(IdentityStoreInvocationContext ctx, IdentityObject identityObject, IdentityObjectCredential credential) throws IdentityException
{
- //TODO: NYI
- throw new NotYetImplementedException();
+ if (credential == null)
+ {
+ throw new IllegalArgumentException();
+ }
+
+ HibernateIdentityObject hibernateObject = safeGet(ctx, identityObject);
+
+ if (supportedFeatures.isCredentialSupported(hibernateObject.getIdentityType(),credential.getType()))
+ {
+
+ HibernateIdentityObjectCredential hibernateCredential = hibernateObject.getCredentials().get(credential.getType().getName());
+
+ if (hibernateCredential == null)
+ {
+ return false;
+ }
+
+ // Handle generic impl
+
+ Object value = null;
+
+ if (credential.getEncodedValue() != null)
+ {
+ value = credential.getEncodedValue();
+ }
+ else
+ {
+ value = credential.getValue();
+ }
+
+ if (value instanceof String && hibernateCredential.getTextValue() != null)
+ {
+ return value.toString().equals(hibernateCredential.getTextValue());
+ }
+ else if (value instanceof byte[] && hibernateCredential.getBinaryValue() != null)
+ {
+ return Arrays.equals((byte[])value, hibernateCredential.getBinaryValue());
+ }
+ else
+ {
+ throw new IdentityException("Not supported credential value: " + value.getClass());
+ }
+ }
+ else
+ {
+ throw new IdentityException("CredentialType not supported for a given IdentityObjectType");
+ }
}
public void updateCredential(IdentityStoreInvocationContext ctx, IdentityObject identityObject, IdentityObjectCredential credential) throws IdentityException
{
- //TODO: NYI
- throw new NotYetImplementedException();
+
+ if (credential == null)
+ {
+ throw new IllegalArgumentException();
+ }
+
+ HibernateIdentityObject hibernateObject = safeGet(ctx, identityObject);
+
+ HibernateEntityManager em = getHibernateEntityManager(ctx);
+
+ if (supportedFeatures.isCredentialSupported(hibernateObject.getIdentityType(),credential.getType()))
+ {
+
+ HibernateIdentityObjectCredentialType hibernateCredentialType = getHibernateIdentityObjectCredentialType(ctx, credential.getType());
+
+ if (hibernateCredentialType == null)
+ {
+ throw new IllegalStateException("Credential type not present in this store: " + credential.getType().getName());
+ }
+
+ HibernateIdentityObjectCredential hibernateCredential = new HibernateIdentityObjectCredential();
+ hibernateCredential.setIdentityObject(hibernateObject);
+ hibernateCredential.setType(hibernateCredentialType);
+
+ Object value = null;
+
+ // Handle generic impl
+
+ if (credential.getEncodedValue() != null)
+ {
+ value = credential.getEncodedValue();
+ }
+ else
+ {
+ value = credential.getValue();
+ }
+
+ if (value instanceof String)
+ {
+ hibernateCredential.setTextValue(value.toString());
+ }
+ else if (value instanceof byte[])
+ {
+ hibernateCredential.setBinaryValue((byte[])value);
+ }
+ else
+ {
+ throw new IdentityException("Not supported credential value: " + value.getClass());
+ }
+
+ em.persist(hibernateCredential);
+
+ hibernateObject.addCredential(hibernateCredential);
+
+ }
+ else
+ {
+ throw new IdentityException("CredentialType not supported for a given IdentityObjectType");
+ }
}
+
+
+
+
+
// Internal
public void addIdentityObjectType(IdentityStoreInvocationContext ctx, IdentityObjectType type) throws IdentityException
@@ -1167,6 +1556,26 @@
return relationshipType;
}
+ private HibernateIdentityObjectCredentialType getHibernateIdentityObjectCredentialType(IdentityStoreInvocationContext ctx, IdentityObjectCredentialType credentialType) throws IdentityException
+ {
+ HibernateEntityManager em = getHibernateEntityManager(ctx);
+
+ HibernateIdentityObjectCredentialType hibernateType = null;
+
+ try
+ {
+ hibernateType = (HibernateIdentityObjectCredentialType)em.getSession().
+ createCriteria(HibernateIdentityObjectCredentialType.class).add(Restrictions.eq("name", credentialType.getName())).uniqueResult();
+ }
+ catch (HibernateException e)
+ {
+ throw new IdentityException("IdentityObjectCredentialType[ " + credentialType.getName() + "] not present in the store.");
+ }
+
+ return hibernateType;
+
+ }
+
public void populateObjectTypes(HibernateEntityManager em, String[] typeNames) throws Exception
{
@@ -1213,6 +1622,30 @@
em.getTransaction().commit();
}
+
+ public void populateCredentialTypes(HibernateEntityManager em, String[] typeNames) throws Exception
+ {
+
+ em.getTransaction().begin();
+
+ for (String typeName : typeNames)
+ {
+ HibernateIdentityObjectCredentialType hibernateType = (HibernateIdentityObjectCredentialType)em.getSession().
+ createCriteria(HibernateIdentityObjectCredentialType.class).add(Restrictions.eq("name", typeName)).uniqueResult();
+
+ if (hibernateType == null)
+ {
+ hibernateType = new HibernateIdentityObjectCredentialType(typeName);
+ em.persist(hibernateType);
+ }
+
+ }
+
+ em.getTransaction().commit();
+ }
+
+
+
public void addRealm(HibernateEntityManager em, String realmName) throws IdentityException
{
@@ -1258,6 +1691,15 @@
{
realm = (HibernateRealm)em.getSession().
createCriteria(HibernateRealm.class).add(Restrictions.eq("name", ctx.getRealmId())).uniqueResult();
+
+
+ // TODO: other way to not lazy initialize realm? special method called on every new session creation
+ if (realm == null)
+ {
+ HibernateRealm newRealm = new HibernateRealm(ctx.getRealmId());
+ em.persist(newRealm);
+ return newRealm;
+ }
}
@@ -1269,6 +1711,11 @@
{
return isRealmAware;
}
+
+ private boolean isAllowNotDefinedAttributes()
+ {
+ return isAllowNotDefinedAttributes;
+ }
private void checkControls(IdentityObjectSearchControl[] controls) throws IdentityException
{
@@ -1276,7 +1723,7 @@
{
for (IdentityObjectSearchControl control : controls)
{
- if (!supportedSearchControls.contains(control.getClass()))
+ if (!supportedIdentityObjectSearchControls.contains(control.getClass()))
{
throw new IdentityException("IdentityObjectSearchControl not supported by this IdentityStore: " + control.getClass());
}
@@ -1284,6 +1731,100 @@
}
}
+ /**
+ * Resolve store mapping for attribute name. If attribute is not mapped and store doesn't allow not defined
+ * attributes throw exception
+ * @param type
+ * @param name
+ * @return
+ */
+ private String resolveAttributeStoreMapping(IdentityObjectType type, String name) throws IdentityException
+ {
+ String mapping = null;
+ if (attributesMetaData.containsKey(type.getName()))
+ {
+ AttributeMetaData amd = attributesMetaData.get(type.getName()).get(name);
+ if (amd != null)
+ {
+ mapping = amd.getStoreMapping() != null ? amd.getStoreMapping() : amd.getName();
+ return mapping;
+ }
+ }
+
+ if (isAllowNotDefinedAttributes())
+ {
+ mapping = name;
+ return mapping;
+ }
+
+ throw new IdentityException("Attribute name is not configured in this store");
+ }
+
+ private String resolveAttributeNameFromStoreMapping(IdentityObjectType type, String mapping)
+ {
+ if (reverseAttributeMappings.containsKey(type.getName()))
+ {
+ Map<String, String> map = reverseAttributeMappings.get(type.getName());
+
+ if (map != null)
+ {
+ String name = map.containsKey(mapping) ? map.get(mapping) : mapping;
+ return name;
+ }
+ }
+
+ if (isAllowNotDefinedAttributes())
+ {
+ return mapping;
+ }
+ return null;
+ }
+
+ //TODO: this kills performance and is present here only as "quick" hack to have the feature present and let to add test cases
+ //TODO: needs to be redone on the hibernate query level
+ private void filterByAttributesValues(Collection<IdentityObject> objects, Map<String, String[]> attrs)
+ {
+ Set<IdentityObject> toRemove = new HashSet<IdentityObject>();
+
+ for (IdentityObject object : objects)
+ {
+ boolean add = true;
+
+ Map<String, String[]> presentAttrs = ((HibernateIdentityObject)object).getAttributesAsMap();
+ for (Map.Entry<String, String[]> entry : attrs.entrySet())
+ {
+ if (presentAttrs.containsKey(entry.getKey()))
+ {
+ Set<String> given = new HashSet<String>(Arrays.asList(entry.getValue()));
+ Set<String> present = new HashSet<String>(Arrays.asList(presentAttrs.get(entry.getKey())));
+
+ for (String s : given)
+ {
+ if (!present.contains(s))
+ {
+ toRemove.add(object);
+ break;
+ }
+ }
+
+ }
+ else
+ {
+ toRemove.add(object);
+ break;
+
+ }
+ }
+ }
+
+ for (IdentityObject identityObject : toRemove)
+ {
+ objects.remove(identityObject);
+ }
+ }
+
+
+
}
Modified: trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreImpl.java
===================================================================
--- trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreImpl.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/main/java/org/jboss/identity/impl/store/ldap/LDAPIdentityStoreImpl.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -40,9 +40,15 @@
import org.jboss.identity.impl.model.ldap.LDAPIdentityObjectRelationshipImpl;
import org.jboss.identity.impl.helper.Tools;
import org.jboss.identity.impl.NotYetImplementedException;
+import org.jboss.identity.impl.api.SortByNameSearchControl;
+import org.jboss.identity.impl.api.PageSearchControl;
+import org.jboss.identity.impl.api.AttributeFilterSearchControl;
+import org.jboss.identity.impl.api.NameFilterSearchControl;
import javax.naming.ldap.LdapContext;
import javax.naming.ldap.LdapName;
+import javax.naming.ldap.Control;
+import javax.naming.ldap.SortControl;
import javax.naming.directory.Attributes;
import javax.naming.directory.Attribute;
import javax.naming.directory.SearchControls;
@@ -88,7 +94,9 @@
// List all supported controls classes
//TODO:
- //supportedSearchControls.add()
+ supportedSearchControls.add(SortByNameSearchControl.class);
+ //supportedSearchControls.add(PageSearchControl.class);
+ //supportedSearchControls.add(AttributeFilterSearchControl.class);
}
public LDAPIdentityStoreImpl(String id)
@@ -100,7 +108,7 @@
{
configuration = new SimpleLDAPIdentityStoreConfiguration(configurationMD);
- supportedFeatures = new FeaturesMetaDataImpl(configurationMD, supportedSearchControls, new HashMap<String, Set<String>>());
+ supportedFeatures = new FeaturesMetaDataImpl(configurationMD, supportedSearchControls);
}
public IdentityStoreSession createIdentityStoreSession()
@@ -482,18 +490,92 @@
// );
// }
- //TODO: controls (name filter)
+ checkControls(controls);
+
+ //TODO: paged control
+
+ PageSearchControl pageSearchControl = null;
+ SortByNameSearchControl sortSearchControl = null;
+ AttributeFilterSearchControl attributeFilterSearchControl = null;
+ NameFilterSearchControl nameFilterSearchControl = null;
+
+ if (controls != null)
+ {
+ for (IdentityObjectSearchControl control : controls)
+ {
+ if (control instanceof PageSearchControl)
+ {
+ pageSearchControl = (PageSearchControl)control;
+ }
+ else if (control instanceof SortByNameSearchControl)
+ {
+ sortSearchControl = (SortByNameSearchControl)control;
+ }
+ else if (control instanceof AttributeFilterSearchControl)
+ {
+ attributeFilterSearchControl = (AttributeFilterSearchControl)control;
+ }
+ else if (control instanceof NameFilterSearchControl)
+ {
+ nameFilterSearchControl = (NameFilterSearchControl)control;
+ }
+
+ }
+ }
+
String nameFilter = "*";
- //TODO: handle paged results and sort
+ //Filter by name
+ if (nameFilterSearchControl != null)
+ {
+ nameFilter = nameFilterSearchControl.getFilter();
+ }
- Context ctx = getLDAPContext(invocationCtx);
+
+ //TODO: handle paged results
+
+ LdapContext ctx = getLDAPContext(invocationCtx);
+
+
checkIOType(type);
List<IdentityObject> objects = new LinkedList<IdentityObject>();
+ LDAPIdentityObjectTypeConfiguration typeConfiguration = getTypeConfiguration(invocationCtx, type);
+
try
{
+ // Sort control
+ if (sortSearchControl != null)
+ {
+ //TODO: make criticallity optional
+ ctx.setRequestControls(new Control[]{
+ new SortControl(typeConfiguration.getIdAttributeName(), Control.NONCRITICAL)
+ });
+ }
+
+ StringBuilder af = new StringBuilder();
+
+ // Filter by attribute values
+ if (attributeFilterSearchControl != null)
+ {
+ af.append("(&");
+
+ for (Map.Entry<String, String[]> stringEntry : attributeFilterSearchControl.getValues().entrySet())
+ {
+ for (String value : stringEntry.getValue())
+ {
+ af.append("(")
+ .append(stringEntry.getKey())
+ .append("=")
+ .append(value)
+ .append(")");
+ }
+ }
+
+ af.append(")");
+ }
+
String filter = getTypeConfiguration(invocationCtx, type).getEntrySearchFilter();
List<SearchResult> sr = null;
@@ -501,23 +583,31 @@
{
Object[] filterArgs = {nameFilter};
- sr = searchIdentityObjects(invocationCtx, type, filter, filterArgs, new String[]{getTypeConfiguration(invocationCtx, type).getIdAttributeName()});
+ sr = searchIdentityObjects(invocationCtx, type, "&(" + filter + ")" + af.toString(), filterArgs, new String[]{typeConfiguration.getIdAttributeName()});
}
else
{
- filter = "(".concat(getTypeConfiguration(invocationCtx, type).getIdAttributeName()).concat("=").concat(nameFilter).concat(")");
- sr = searchIdentityObjects(invocationCtx, type, filter, null, new String[]{getTypeConfiguration(invocationCtx, type).getIdAttributeName()});
+ filter = "(".concat(typeConfiguration.getIdAttributeName()).concat("=").concat(nameFilter).concat(")");
+ sr = searchIdentityObjects(invocationCtx, type, "&(" + filter + ")" + af.toString(), null, new String[]{typeConfiguration.getIdAttributeName()});
}
for (SearchResult res : sr)
{
- ctx = (Context)res.getObject();
+ ctx = (LdapContext)res.getObject();
String dn = ctx.getNameInNamespace();
objects.add(createIdentityObjectInstance(invocationCtx, type, res.getAttributes(), dn));
}
ctx.close();
+
+ // Post sort if the order was descending
+ if (sortSearchControl != null && !sortSearchControl.isAscending());
+ {
+ //TODO: rather sucks for the performance but I don't see how to do this with JNDI SortControl
+ //TODO: check if result was sorted (if the control was NONCRITICAL) to save some cycles
+ Collections.reverse(objects);
+ }
return objects;
}
@@ -525,7 +615,7 @@
{
//log.debug("No identity object found with name: " + name, e);
}
- catch (NamingException e)
+ catch (Exception e)
{
throw new IdentityException("IdentityObject search failed.", e);
}
@@ -665,6 +755,26 @@
//TODO: handle paged results and sort
+ checkControls(controls);
+
+ PageSearchControl pageSearchControl = null;
+ SortByNameSearchControl sortSearchControl = null;
+
+ if (controls != null)
+ {
+ for (IdentityObjectSearchControl control : controls)
+ {
+ if (control instanceof PageSearchControl)
+ {
+ pageSearchControl = (PageSearchControl)control;
+ }
+ else if (control instanceof SortByNameSearchControl)
+ {
+ sortSearchControl = (SortByNameSearchControl)control;
+ }
+ }
+ }
+
Set<IdentityObjectRelationship> relationships = new HashSet<IdentityObjectRelationship>();
LDAPIdentityObjectImpl ldapFromIO = getSafeLDAPIO(ctx, identity);
@@ -704,12 +814,15 @@
break;
}
}
+
+ //TODO: need to be sorted/paginated manually
}
- // if not parent all parent entries need to be found
+ // if not parent then all parent entries need to be found
else
{
//TODO:
+ //TODO: apply sort/pagination ldap control
throw new NotYetImplementedException();
}
@@ -767,8 +880,6 @@
LdapContext ldapContext = getLDAPContext(ctx);
// Check posibilities
- //TODO: Supported features should handle information from type configurations
-
if (!getSupportedFeatures().isRelationshipTypeSupported(fromIdentity.getIdentityType(), toIdentity.getIdentityType(), relationshipType))
{
throw new IdentityException("Relationship not supported");
@@ -776,7 +887,7 @@
try
{
- //construct new member attribute values
+ // Construct new member attribute values
Attributes attrs = new BasicAttributes(true);
Attribute member = new BasicAttribute(fromTypeConfig.getMembershipAttributeName());
@@ -1504,5 +1615,18 @@
return this.getClass().getName() + "[" + getId() +"]";
}
+ private void checkControls(IdentityObjectSearchControl[] controls) throws IdentityException
+ {
+ if (controls != null)
+ {
+ for (IdentityObjectSearchControl control : controls)
+ {
+ if (!supportedSearchControls.contains(control.getClass()))
+ {
+ throw new IdentityException("IdentityObjectSearchControl not supported by this IdentityStore: " + control.getClass());
+ }
+ }
+ }
+ }
}
Modified: trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/CommonIdentityStoreTest.java
===================================================================
--- trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/CommonIdentityStoreTest.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/CommonIdentityStoreTest.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -23,12 +23,22 @@
package org.jboss.identity.impl.store;
import org.jboss.identity.spi.model.IdentityObject;
+import org.jboss.identity.spi.credential.IdentityObjectCredential;
+import org.jboss.identity.spi.searchcontrol.IdentityObjectSearchControl;
+import org.jboss.identity.impl.api.PasswordCredential;
+import org.jboss.identity.impl.api.BinaryCredential;
+import org.jboss.identity.impl.api.NameFilterSearchControl;
+import org.jboss.identity.impl.api.SortByNameSearchControl;
+import org.jboss.identity.impl.api.AttributeFilterSearchControl;
+import org.jboss.identity.impl.api.PageSearchControl;
+import org.jboss.identity.impl.model.hibernate.HibernateIdentityObject;
+import org.opends.server.controls.PagedResultsControl;
import java.util.Collection;
-import java.util.Set;
import java.util.Map;
import java.util.HashMap;
-import java.util.HashSet;
+import java.util.Random;
+import java.util.List;
import junit.framework.Assert;
@@ -61,8 +71,8 @@
testContext.begin();
- IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.USER);
- IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva", IdentityTypeEnum.USER);
+ IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.IDENTITY);
+ IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva", IdentityTypeEnum.IDENTITY);
IdentityObject group1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Devision1", IdentityTypeEnum.ORGANIZATION);
IdentityObject group2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Devision2", IdentityTypeEnum.ORGANIZATION);
@@ -72,7 +82,7 @@
testContext.flush();
assertEquals(0, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.ROLE));
- assertEquals(2, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.USER));
+ assertEquals(2, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.IDENTITY));
assertEquals(4, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.ORGANIZATION));
testContext.flush();
@@ -81,14 +91,14 @@
testContext.getStore().removeIdentityObject(testContext.getCtx(), group1);
testContext.getStore().removeIdentityObject(testContext.getCtx(), group2);
- assertEquals(1, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.USER));
+ assertEquals(1, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.IDENTITY));
assertEquals(2, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.ORGANIZATION));
testContext.getStore().removeIdentityObject(testContext.getCtx(), user2);
testContext.getStore().removeIdentityObject(testContext.getCtx(), group3);
testContext.getStore().removeIdentityObject(testContext.getCtx(), group4);
- assertEquals(0, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.USER));
+ assertEquals(0, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.IDENTITY));
assertEquals(0, testContext.getStore().getIdentityObjectsCount(testContext.getCtx(), IdentityTypeEnum.ORGANIZATION));
testContext.commit();
@@ -100,8 +110,8 @@
testContext.begin();
- IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.USER);
- IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva", IdentityTypeEnum.USER);
+ IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.IDENTITY);
+ IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva", IdentityTypeEnum.IDENTITY);
IdentityObject group1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Devision1", IdentityTypeEnum.ORGANIZATION);
IdentityObject group2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Devision2", IdentityTypeEnum.ORGANIZATION);
@@ -110,13 +120,13 @@
testContext.flush();
- IdentityObject xx = testContext.getStore().findIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.USER);
+ IdentityObject xx = testContext.getStore().findIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.IDENTITY);
assertEquals(xx.getId(), user1.getId());
xx = testContext.getStore().findIdentityObject(testContext.getCtx(), user2.getId());
assertEquals(xx.getId(), user2.getId());
- Collection results = testContext.getStore().findIdentityObject(testContext.getCtx(), IdentityTypeEnum.USER, null);
+ Collection results = testContext.getStore().findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, null);
assertEquals(2, results.size());
results = testContext.getStore().findIdentityObject(testContext.getCtx(), IdentityTypeEnum.ORGANIZATION, null);
@@ -135,8 +145,8 @@
testContext.begin();
- IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.USER);
- IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva", IdentityTypeEnum.USER);
+ IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.IDENTITY);
+ IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva", IdentityTypeEnum.IDENTITY);
testContext.flush();
@@ -231,8 +241,8 @@
testContext.begin();
- IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.USER);
- IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva", IdentityTypeEnum.USER);
+ IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.IDENTITY);
+ IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva", IdentityTypeEnum.IDENTITY);
IdentityObject group1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Devision1", IdentityTypeEnum.ORGANIZATION);
IdentityObject group2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Devision2", IdentityTypeEnum.ORGANIZATION);
@@ -241,8 +251,8 @@
testContext.flush();
- testContext.getStore().createRelationship(testContext.getCtx(), group1, user1, RelationshipTypeEnum.MEMBER, null, false);
- testContext.getStore().createRelationship(testContext.getCtx(), group2, user1, RelationshipTypeEnum.MEMBER, null, false);
+ testContext.getStore().createRelationship(testContext.getCtx(), group1, user1, RelationshipTypeEnum.JBOSS_IDENTITY_MEMBERSHIP, null, false);
+ testContext.getStore().createRelationship(testContext.getCtx(), group2, user1, RelationshipTypeEnum.JBOSS_IDENTITY_MEMBERSHIP, null, false);
testContext.flush();
@@ -251,7 +261,7 @@
assertEquals(1, testContext.getStore().resolveRelationships(testContext.getCtx(), group2, user1).size());
assertEquals(0, testContext.getStore().resolveRelationships(testContext.getCtx(), user1, group2).size());
- testContext.getStore().removeRelationship(testContext.getCtx(), group2, user1, RelationshipTypeEnum.MEMBER, null);
+ testContext.getStore().removeRelationship(testContext.getCtx(), group2, user1, RelationshipTypeEnum.JBOSS_IDENTITY_MEMBERSHIP, null);
testContext.flush();
@@ -271,4 +281,228 @@
testContext.commit();
}
-}
+
+ public void testPasswordCredential() throws Exception
+ {
+ testContext.begin();
+
+ IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam", IdentityTypeEnum.IDENTITY);
+ IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva", IdentityTypeEnum.IDENTITY);
+
+ IdentityObjectCredential passwordCredential1 = new PasswordCredential("SamplePasswordOne");
+ IdentityObjectCredential passwordCredential2 = new PasswordCredential("SamplePasswordTwo");
+
+ // If PASSWORD is supported
+ assertTrue(testContext.getStore().getSupportedFeatures().isCredentialSupported(IdentityTypeEnum.IDENTITY, passwordCredential1.getType()));
+
+ testContext.getStore().updateCredential(testContext.getCtx(), user1, passwordCredential1);
+ testContext.getStore().updateCredential(testContext.getCtx(), user2, passwordCredential2);
+
+ assertTrue(testContext.getStore().validateCredential(testContext.getCtx(), user1, passwordCredential1));
+ assertTrue(testContext.getStore().validateCredential(testContext.getCtx(), user2, passwordCredential2));
+ assertFalse(testContext.getStore().validateCredential(testContext.getCtx(), user1, passwordCredential2));
+ assertFalse(testContext.getStore().validateCredential(testContext.getCtx(), user2, passwordCredential1));
+
+ testContext.commit();
+ }
+
+ public void testBinaryCredential() throws Exception
+ {
+ testContext.begin();
+
+ IdentityObject user1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Adam2", IdentityTypeEnum.IDENTITY);
+ IdentityObject user2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Eva2", IdentityTypeEnum.IDENTITY);
+
+ Random random = new Random();
+
+ byte[] data1 = new byte[5120];
+ random.nextBytes(data1);
+ byte[] data2 = new byte[1024];
+ random.nextBytes(data2);
+
+ IdentityObjectCredential binaryCredential1 = new BinaryCredential(data1);
+ IdentityObjectCredential binaryCredential2 = new BinaryCredential(data2);
+
+
+ // If BINARY is supported
+ assertTrue(testContext.getStore().getSupportedFeatures().isCredentialSupported(IdentityTypeEnum.IDENTITY, binaryCredential1.getType()));
+
+ testContext.getStore().updateCredential(testContext.getCtx(), user1, binaryCredential1);
+ testContext.getStore().updateCredential(testContext.getCtx(), user2, binaryCredential2);
+
+ assertTrue(testContext.getStore().validateCredential(testContext.getCtx(), user1, binaryCredential1));
+ assertTrue(testContext.getStore().validateCredential(testContext.getCtx(), user2, binaryCredential2));
+ assertFalse(testContext.getStore().validateCredential(testContext.getCtx(), user1, binaryCredential2));
+ assertFalse(testContext.getStore().validateCredential(testContext.getCtx(), user2, binaryCredential1));
+
+ testContext.commit();
+ }
+
+
+
+
+ public void testControls() throws Exception
+ {
+ testContext.begin();
+
+ IdentityObject group1 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Division1", IdentityTypeEnum.IDENTITY);
+ IdentityObject group2 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Division2", IdentityTypeEnum.IDENTITY);
+ IdentityObject group3 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Division3", IdentityTypeEnum.IDENTITY);
+ IdentityObject group4 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Company1", IdentityTypeEnum.IDENTITY);
+ IdentityObject group5 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Company2", IdentityTypeEnum.IDENTITY);
+ IdentityObject group6 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Entity1", IdentityTypeEnum.IDENTITY);
+ IdentityObject group7 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Entity2", IdentityTypeEnum.IDENTITY);
+ IdentityObject group8 = testContext.getStore().createIdentityObject(testContext.getCtx(), "Entity3", IdentityTypeEnum.IDENTITY);
+
+ Collection<IdentityObject> results = null;
+ IdentityObjectSearchControl control = null;
+
+ // TODO: by RelationshipType
+
+ if (testContext.getStore().getSupportedFeatures().isControlSupported(IdentityTypeEnum.IDENTITY, NameFilterSearchControl.class))
+ {
+ control = new NameFilterSearchControl("*");
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(8, results.size());
+
+ control = new NameFilterSearchControl("D*");
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(3, results.size());
+
+ control = new NameFilterSearchControl("*2");
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(3, results.size());
+
+ control = new NameFilterSearchControl("*3");
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(2, results.size());
+
+ control = new NameFilterSearchControl("Company1");
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(1, results.size());
+
+ control = new NameFilterSearchControl("Totoro");
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(0, results.size());
+ }
+
+
+ if (testContext.getStore().getSupportedFeatures().isControlSupported(IdentityTypeEnum.IDENTITY, PageSearchControl.class))
+ {
+
+ control = new PageSearchControl(0, 3);
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(3, results.size());
+
+ control = new PageSearchControl(2, 2);
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(2, results.size());
+
+ }
+ if (testContext.getStore().getSupportedFeatures().isControlSupported(IdentityTypeEnum.IDENTITY, SortByNameSearchControl.class))
+ {
+
+
+ control = new SortByNameSearchControl(true);
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(8, results.size());
+
+ // Just check the first and the last one
+ assertEquals("Company1", ((List<IdentityObject>)results).get(0).getName());
+ assertEquals("Entity3", ((List<IdentityObject>)results).get(7).getName());
+
+
+ // And reverse order
+ control = new SortByNameSearchControl(false);
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(8, results.size());
+
+ // Just check the first and the last one
+ assertEquals("Company1", ((List<IdentityObject>)results).get(7).getName());
+ assertEquals("Entity3", ((List<IdentityObject>)results).get(0).getName());
+
+
+
+
+
+ // Combine controls to check that the results are diffrent for pagination
+ if (testContext.getStore().getSupportedFeatures().isControlSupported(IdentityTypeEnum.IDENTITY, PageSearchControl.class))
+ {
+ control = new SortByNameSearchControl(true);
+ IdentityObjectSearchControl control2 = new PageSearchControl(0, 3);
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control, control2});
+
+ assertEquals(3, results.size());
+ assertEquals("Company1", ((List<IdentityObject>)results).get(0).getName());
+ assertEquals("Division1", ((List<IdentityObject>)results).get(2).getName());
+
+ control2 = new PageSearchControl(3, 1);
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control, control2});
+
+ assertEquals(1, results.size());
+
+ assertEquals(1, results.size());
+ assertEquals("Division2", ((List<IdentityObject>)results).get(0).getName());
+
+ }
+
+
+ }
+
+ if (testContext.getStore().getSupportedFeatures().isControlSupported(IdentityTypeEnum.IDENTITY, AttributeFilterSearchControl.class))
+ {
+ Map<String, String[]> attrs = new HashMap<String, String[]>();
+ attrs.put("phone", new String[] {"777 777 777"});
+ attrs.put("description", new String[] {"sample desc"});
+
+ testContext.getStore().addAttributes(testContext.getCtx(), group1, attrs);
+
+ control = new AttributeFilterSearchControl(attrs);
+
+ results = testContext.getStore().
+ findIdentityObject(testContext.getCtx(), IdentityTypeEnum.IDENTITY, new IdentityObjectSearchControl[]{control});
+
+ assertEquals(1, results.size());
+
+ }
+
+ testContext.commit();
+
+ }
+
+
+}
\ No newline at end of file
Modified: trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/RelationshipTypeEnum.java
===================================================================
--- trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/RelationshipTypeEnum.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/RelationshipTypeEnum.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -31,7 +31,8 @@
*/
public enum RelationshipTypeEnum implements IdentityObjectRelationshipType
{
- MEMBER;
+ JBOSS_IDENTITY_MEMBERSHIP,
+ JBOSS_IDENTITY_ROLE;
public String getName()
{
Modified: trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/hibernate/HibernateIdentityStoreTestCase.java
===================================================================
--- trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/hibernate/HibernateIdentityStoreTestCase.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/hibernate/HibernateIdentityStoreTestCase.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -31,6 +31,8 @@
import org.jboss.identity.spi.store.IdentityStoreSession;
import org.jboss.identity.spi.searchcontrol.IdentityObjectSearchControl;
import org.jboss.identity.spi.credential.IdentityObjectCredentialType;
+import org.jboss.identity.spi.configuration.metadata.IdentityStoreConfigurationMetaData;
+import org.jboss.identity.spi.configuration.metadata.IdentityConfigurationMetaData;
import org.jboss.identity.impl.store.hibernate.HibernateIdentityStoreImpl;
import org.jboss.identity.impl.store.hibernate.HibernateTestBase;
import org.jboss.identity.impl.store.RelationshipTypeEnum;
@@ -39,6 +41,10 @@
import org.jboss.identity.impl.store.IdentityStoreTestContext;
import org.jboss.identity.impl.store.FeaturesMetaDataImpl;
import org.jboss.identity.impl.model.hibernate.HibernateRealm;
+import org.jboss.identity.impl.configuration.metadata.IdentityStoreConfigurationMetaDataImpl;
+import org.jboss.identity.impl.configuration.metadata.IdentityObjectTypeMetaDataImpl;
+import org.jboss.identity.impl.configuration.metadata.IdentityConfigurationMetaDataImpl;
+import org.jboss.identity.impl.configuration.jaxb2.JAXB2IdentityConfiguration;
import org.jboss.identity.exception.IdentityException;
import org.hibernate.ejb.HibernateEntityManager;
@@ -47,6 +53,11 @@
import java.util.Map;
import java.util.HashMap;
import java.util.HashSet;
+import java.util.List;
+import java.util.ArrayList;
+import java.util.Arrays;
+import java.util.LinkedList;
+import java.io.File;
/**
* @author <a href="mailto:boleslaw.dawidowicz at redhat.com">Boleslaw Dawidowicz</a>
@@ -74,57 +85,39 @@
{
super.setUp();
- store = new HibernateIdentityStoreImpl("test-id")
+ IdentityConfigurationMetaData configurationMD = JAXB2IdentityConfiguration
+ .createConfigurationMetaData(new File("src/test/resources/store-test-config.xml"));
+
+ IdentityStoreConfigurationMetaData storeMD = null;
+
+ for (IdentityStoreConfigurationMetaData metaData : configurationMD.getIdentityStores())
{
+ if (metaData.getId().equals("HibernateTestStore"))
+ {
+ storeMD = metaData;
+ break;
+ }
+ }
+ store = new HibernateIdentityStoreImpl("HibernateTestStore")
+ {
+
protected HibernateEntityManager getHibernateEntityManager(IdentityStoreInvocationContext ctx)
{
return em;
}
@Override
- public FeaturesMetaData getSupportedFeatures()
+ protected HibernateEntityManager bootstrapHibernateEntityManager(String persistenceUnit) throws IdentityException
{
- return new FeaturesMetaData()
- {
- public boolean isControlSupported(IdentityObjectType identityObjectType, IdentityObjectSearchControl control)
- {
- return true;
- }
+ return em;
+ }
- public boolean isControlSupported(IdentityObjectType identityObjectType, Class controlClazz)
- {
- return true;
- }
+ };
- public Set<String> getSupportedIdentityObjectTypes()
- {
- return null;
- }
+ store.bootstrap(storeMD);
- public boolean isIdentityObjectTypeSupported(IdentityObjectType identityObjectType)
- {
- return true;
- }
- public boolean isRelationshipTypeSupported(IdentityObjectType fromType, IdentityObjectType toType, IdentityObjectRelationshipType relationshipType) throws IdentityException
- {
- return true;
- }
-
- public Set<String> getSupportedRelationshipTypes()
- {
- return null;
- }
-
- public boolean isCredentialSupported(IdentityObjectType identityObjectType, IdentityObjectCredentialType credentialType)
- {
- return true;
- }
- };
- }
- };
-
ctx = new IdentityStoreInvocationContext()
{
public IdentityStoreSession getIdentityStoreSession()
@@ -138,51 +131,9 @@
}
};
- populateIdentityTypes();
- populateRelationshipTypes();
- em.getTransaction().begin();
-
- HibernateRealm realm = new HibernateRealm(HibernateIdentityStoreImpl.DEFAULT_REALM_NAME);
- em.persist(realm);
-
- em.getTransaction().commit();
-
-
}
- private void populateRelationshipTypes() throws Exception
- {
-
- em.getTransaction().begin();
-
- RelationshipTypeEnum types[] = RelationshipTypeEnum.values();
-
- for (int i = 0; i < types.length; i++)
- {
- RelationshipTypeEnum type = types[i];
- store.addIdentityObjectRelationshipType(ctx, type);
- }
-
- em.getTransaction().commit();
-
- }
-
- private void populateIdentityTypes() throws Exception
- {
- em.getTransaction().begin();
-
- IdentityTypeEnum types[] = IdentityTypeEnum.values();
-
- for (int i = 0; i < types.length; i++)
- {
- IdentityTypeEnum type = types[i];
- store.addIdentityObjectType(ctx, type);
- }
-
- em.getTransaction().commit();
- }
-
public void begin() throws Exception
{
em.getTransaction().begin();
@@ -230,8 +181,8 @@
em.getTransaction().begin();
- IdentityObject user1 = store.createIdentityObject(ctx, "Adam", IdentityTypeEnum.USER);
- IdentityObject user2 = store.createIdentityObject(ctx, "Eva", IdentityTypeEnum.USER);
+ IdentityObject user1 = store.createIdentityObject(ctx, "Adam", IdentityTypeEnum.IDENTITY);
+ IdentityObject user2 = store.createIdentityObject(ctx, "Eva", IdentityTypeEnum.IDENTITY);
em.flush();
@@ -307,8 +258,6 @@
em.flush();
- Set<String> names = new HashSet<String>();
- names.add("key3");
store.removeAttributes(ctx, user1, new String[] {"key3"});
em.flush();
@@ -324,10 +273,18 @@
public void testRelationships() throws Exception
{
-
commonTest.testRelationships();
+ }
+ public void testCredentials() throws Exception
+ {
+ commonTest.testPasswordCredential();
+ commonTest.testBinaryCredential();
}
+ public void testControls() throws Exception
+ {
+ commonTest.testControls();
+ }
}
Modified: trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/hibernate/HibernateModelTestCase.java
===================================================================
--- trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/hibernate/HibernateModelTestCase.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/test/java/org/jboss/identity/impl/store/hibernate/HibernateModelTestCase.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -268,8 +268,8 @@
values1.add("Val3");
- user1.setAttribute("simple1", values1);
- user1.setAttribute("simple2", values1);
+ user1.updateAttribute("simple1", new String[]{"Val1", "Val2", "Val3"});
+ user1.updateAttribute("simple2", new String[]{"Val1", "Val2", "Val3"});
em.getTransaction().commit();
@@ -277,10 +277,10 @@
em.getTransaction().begin();
- user1 = em.find(HibernateIdentityObject.class, new Long(user1.getId()));
- assertEquals(2, user1.getAttributes().entrySet().size() );
- assertNotNull(user1.getAttributes().get("simple1"));
- assertEquals(3, user1.getAttributes().get("simple1").length);
+// user1 = em.find(HibernateIdentityObject.class, new Long(user1.getId()));
+// assertEquals(2, user1.getProfileAttributes().entrySet().size() );
+// assertNotNull(user1.getProfileAttributes().get("simple1"));
+// assertEquals(3, user1.getProfileAttributes().get("simple1").length);
em.getTransaction().commit();
Modified: trunk/identity-impl/src/test/resources/META-INF/persistence.xml
===================================================================
--- trunk/identity-impl/src/test/resources/META-INF/persistence.xml 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/test/resources/META-INF/persistence.xml 2008-12-02 18:51:34 UTC (rev 124)
@@ -11,6 +11,8 @@
<class>org.jboss.identity.impl.model.hibernate.HibernateRealm</class>
<class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObject</class>
+ <class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectCredential</class>
+ <class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectCredentialType</class>
<class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectAttribute</class>
<class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectType</class>
<class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectRelationship</class>
@@ -37,6 +39,8 @@
<class>org.jboss.identity.impl.model.hibernate.HibernateRealm</class>
<class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObject</class>
+ <class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectCredential</class>
+ <class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectCredentialType</class>
<class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectAttribute</class>
<class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectType</class>
<class>org.jboss.identity.impl.model.hibernate.HibernateIdentityObjectRelationship</class>
Modified: trunk/identity-impl/src/test/resources/identity-config.xml
===================================================================
--- trunk/identity-impl/src/test/resources/identity-config.xml 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/test/resources/identity-config.xml 2008-12-02 18:51:34 UTC (rev 124)
@@ -128,6 +128,7 @@
<identity-object-type>
<name></name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
@@ -139,6 +140,7 @@
<identity-object-type-ref></identity-object-type-ref>
</relationship>
</relationships>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
@@ -157,6 +159,11 @@
<identity-object-type>
<name></name>
<relationships/>
+ <credentials>
+ <credential-type></credential-type>
+ <credential-type></credential-type>
+ <credential-type></credential-type>
+ </credentials>
<attributes>
<attribute>
<name></name>
@@ -202,6 +209,7 @@
<identity-object-type-ref></identity-object-type-ref>
</relationship>
</relationships>
+ <credentials/>
<attributes>
<attribute>
<name></name>
Modified: trunk/identity-impl/src/test/resources/identity-config.xsd
===================================================================
--- trunk/identity-impl/src/test/resources/identity-config.xsd 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/test/resources/identity-config.xsd 2008-12-02 18:51:34 UTC (rev 124)
@@ -79,6 +79,11 @@
<xs:element type="xs:string" name="identity-object-type-name"/>
</xs:sequence>
</xs:complexType>
+ <xs:complexType name="credentialsType">
+ <xs:sequence>
+ <xs:element type="xs:string" name="credential-type" maxOccurs="unbounded" minOccurs="0"/>
+ </xs:sequence>
+ </xs:complexType>
<xs:complexType name="repositoriesType">
<xs:sequence>
<xs:element type="urn:repositoryType" name="repository" maxOccurs="unbounded" minOccurs="0" xmlns:urn="urn:jboss:identity:config:v0_1"/>
@@ -151,6 +156,13 @@
</xs:sequence>
</xs:complexType>
</xs:element>
+ <xs:element name="credentials">
+ <xs:complexType>
+ <xs:sequence>
+ <xs:element type="xs:string" name="credential-type" maxOccurs="unbounded" minOccurs="0"/>
+ </xs:sequence>
+ </xs:complexType>
+ </xs:element>
<xs:element name="attributes">
<xs:complexType>
<xs:sequence>
@@ -171,8 +183,24 @@
<xs:sequence>
<xs:element type="xs:string" name="name"/>
<xs:element type="xs:string" name="mapping"/>
- <xs:element type="xs:string" name="isRequired"/>
- <xs:element type="xs:string" name="isMultivalued"/>
+ <xs:element name="isRequired">
+ <xs:simpleType>
+ <xs:restriction base="xs:string">
+ <xs:enumeration value=""/>
+ <xs:enumeration value="true"/>
+ <xs:enumeration value="false"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:element>
+ <xs:element name="isMultivalued">
+ <xs:simpleType>
+ <xs:restriction base="xs:string">
+ <xs:enumeration value=""/>
+ <xs:enumeration value="true"/>
+ <xs:enumeration value="false"/>
+ </xs:restriction>
+ </xs:simpleType>
+ </xs:element>
<xs:element type="xs:string" name="isReadOnly" minOccurs="0"/>
</xs:sequence>
</xs:complexType>
Modified: trunk/identity-impl/src/test/resources/organization-test-config.xml
===================================================================
--- trunk/identity-impl/src/test/resources/organization-test-config.xml 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-impl/src/test/resources/organization-test-config.xml 2008-12-02 18:51:34 UTC (rev 124)
@@ -157,72 +157,86 @@
<identity-object-type>
<name>IDENTITY</name>
<relationships/>
+ <credentials>
+ <credential-type>PASSWORD</credential-type>
+ </credentials>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>ORGANIZATION</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>ORGANIZATION_UNIT</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>DIVISION</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>DEPARTMENT</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>PROJECT</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>PEOPLE</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>ADMINISTRATION</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>COMMUNITY</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>OFFICE</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>SECURITY</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
<identity-object-type>
<name>SYSTEM</name>
<relationships/>
+ <credentials/>
<attributes/>
<options/>
</identity-object-type>
@@ -240,6 +254,14 @@
<name>populateIdentityObjectTypes</name>
<value>true</value>
</option>
+ <option>
+ <name>allowNotDefinedAttributes</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>isRealmAware</name>
+ <value>true</value>
+ </option>
</options>
</identity-store>
<identity-store>
@@ -251,6 +273,9 @@
<identity-object-type>
<name>IDENTITY</name>
<relationships/>
+ <credentials>
+ <credential-type>PASSWORD</credential-type>
+ </credentials>
<attributes>
<attribute>
<name>phone</name>
@@ -312,6 +337,7 @@
<identity-object-type-ref>GROUP</identity-object-type-ref>
</relationship>
</relationships>
+ <credentials/>
<attributes/>
<options>
<option>
@@ -357,6 +383,7 @@
<identity-object-type-ref>IDENTITY</identity-object-type-ref>
</relationship>
</relationships>
+ <credentials/>
<attributes/>
<options>
<option>
Copied: trunk/identity-impl/src/test/resources/store-test-config.xml (from rev 122, trunk/identity-impl/src/test/resources/organization-test-config.xml)
===================================================================
--- trunk/identity-impl/src/test/resources/store-test-config.xml (rev 0)
+++ trunk/identity-impl/src/test/resources/store-test-config.xml 2008-12-02 18:51:34 UTC (rev 124)
@@ -0,0 +1,339 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<jboss-identity xmlns="urn:jboss:identity:config:v0_1"
+ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
+ xsi:schemaLocation="urn:jboss:identity:config:v0_1 identity-config.xsd">
+ <realms>
+ <realm>
+ <id>realm://Dymmy</id>
+ <repository-id-ref>X</repository-id-ref>
+ <identity-type-mappings>
+ <identity-mapping>IDENTITY</identity-mapping>
+ </identity-type-mappings>
+ </realm>
+ </realms>
+ <repositories>
+ <repository>
+ <id>X</id>
+ <class>X</class>
+ <external-config/>
+ <default-identity-store-id>HibernateTestStore</default-identity-store-id>
+ <default-attribute-store-id>HibernateTestStore</default-attribute-store-id>
+ <identity-store-mappings>
+ <identity-store-mapping>
+ <identity-store-id>HibernateTestStore</identity-store-id>
+ <identity-object-types/>
+ <options/>
+ </identity-store-mapping>
+ </identity-store-mappings>
+ </repository>
+ </repositories>
+ <stores>
+ <attribute-stores/>
+ <identity-stores>
+ <identity-store>
+ <id>HibernateTestStore</id>
+ <class>org.jboss.identity.impl.store.hibernate.HibernateIdentityStoreImpl</class>
+ <external-config/>
+ <supported-relationship-types>
+ <relationship-type>JBOSS_IDENTITY_MEMBERSHIP</relationship-type>
+ <relationship-type>JBOSS_IDENTITY_ROLE</relationship-type>
+ </supported-relationship-types>
+ <supported-identity-object-types>
+ <identity-object-type>
+ <name>IDENTITY</name>
+ <relationships/>
+ <credentials>
+ <credential-type>PASSWORD</credential-type>
+ <credential-type>BINARY</credential-type>
+ </credentials>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>ORGANIZATION</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>ORGANIZATION_UNIT</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>DIVISION</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>DEPARTMENT</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>PROJECT</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>PEOPLE</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>ADMINISTRATION</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>COMMUNITY</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>OFFICE</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>SECURITY</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>ROLE</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ <identity-object-type>
+ <name>SYSTEM</name>
+ <relationships/>
+ <credentials/>
+ <attributes/>
+ <options/>
+ </identity-object-type>
+ </supported-identity-object-types>
+ <options>
+ <option>
+ <name>persistenceUnit</name>
+ <value>jboss-identity-model1</value>
+ </option>
+ <option>
+ <name>populateRelationshipTypes</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>populateIdentityObjectTypes</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>isRealmAware</name>
+ <value>false</value>
+ </option>
+ <option>
+ <name>allowNotDefinedAttributes</name>
+ <value>true</value>
+ </option>
+ </options>
+ </identity-store>
+ <identity-store>
+ <id>LDAPTestStore</id>
+ <class>org.jboss.identity.impl.store.ldap.LDAPIdentityStoreImpl</class>
+ <external-config/>
+ <supported-relationship-types/>
+ <supported-identity-object-types>
+ <identity-object-type>
+ <name>IDENTITY</name>
+ <relationships/>
+ <credentials>
+ <credential-type>PASSWORD</credential-type>
+ </credentials>
+ <attributes>
+ <attribute>
+ <name>phone</name>
+ <mapping>telephoneNumber</mapping>
+ <isRequired/>
+ <isMultivalued/>
+ <isReadOnly/>
+ </attribute>
+ <attribute>
+ <name>description</name>
+ <mapping>description</mapping>
+ <isRequired/>
+ <isMultivalued/>
+ <isReadOnly/>
+ </attribute>
+ <attribute>
+ <name>carLicense</name>
+ <mapping>carLicense</mapping>
+ <isRequired/>
+ <isMultivalued/>
+ <isReadOnly/>
+ </attribute>
+ </attributes>
+ <options>
+ <option>
+ <name>idAttributeName</name>
+ <value>uid</value>
+ </option>
+ <option>
+ <name>ctxDNs</name>
+ <value>ou=People,o=test,dc=portal,dc=example,dc=com</value>
+ </option>
+ <option>
+ <name>allowCreateEntry</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>createEntryAttributeValues</name>
+ <value>objectClass=top</value>
+ <value>objectClass=inetOrgPerson</value>
+ <value>sn= </value>
+ <value>cn= </value>
+ </option>
+ </options>
+ </identity-object-type>
+ <identity-object-type>
+ <name>GROUP</name>
+ <relationships>
+ <relationship>
+ <relationship-type-ref/>
+ <identity-object-type-ref>IDENTITY</identity-object-type-ref>
+ </relationship>
+ <relationship>
+ <relationship-type-ref/>
+ <identity-object-type-ref>ROLE</identity-object-type-ref>
+ </relationship>
+ <relationship>
+ <relationship-type-ref/>
+ <identity-object-type-ref>GROUP</identity-object-type-ref>
+ </relationship>
+ </relationships>
+ <credentials/>
+ <attributes/>
+ <options>
+ <option>
+ <name>idAttributeName</name>
+ <value>cn</value>
+ </option>
+ <option>
+ <name>ctxDNs</name>
+ <value>ou=Roles,o=test,dc=portal,dc=example,dc=com</value>
+ </option>
+ <!--<option>-->
+ <!--<name>entrySearchFilter</name>-->
+ <!--<value></value>-->
+ <!--</option>-->
+ <option>
+ <name>allowCreateEntry</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>membershipAttributeName</name>
+ <value>member</value>
+ </option>
+ <option>
+ <name>isMembershipAttributeDN</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>allowEmptyMemberships</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>createEntryAttributeValues</name>
+ <value>objectClass=top</value>
+ <value>objectClass=groupOfNames</value>
+ </option>
+ </options>
+ </identity-object-type>
+ <identity-object-type>
+ <name>ROLE</name>
+ <relationships>
+ <relationship>
+ <relationship-type-ref/>
+ <identity-object-type-ref>IDENTITY</identity-object-type-ref>
+ </relationship>
+ </relationships>
+ <credentials/>
+ <attributes/>
+ <options>
+ <option>
+ <name>idAttributeName</name>
+ <value>cn</value>
+ </option>
+ <option>
+ <name>ctxDNs</name>
+ <value>ou=Roles,o=test,dc=portal,dc=example,dc=com</value>
+ </option>
+ <!--<option>-->
+ <!--<name>entrySearchFilter</name>-->
+ <!--<value></value>-->
+ <!--</option>-->
+ <option>
+ <name>allowCreateEntry</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>membershipAttributeName</name>
+ <value>member</value>
+ </option>
+ <option>
+ <name>isMembershipAttributeDN</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>allowEmptyMemberships</name>
+ <value>true</value>
+ </option>
+ <option>
+ <name>createEntryAttributeValues</name>
+ <value>objectClass=top</value>
+ <value>objectClass=groupOfNames</value>
+ </option>
+ </options>
+ </identity-object-type>
+ </supported-identity-object-types>
+ <options>
+ <option>
+ <name>providerURL</name>
+ <value>ldap://localhost:10389</value>
+ </option>
+ <option>
+ <name>adminDN</name>
+ <value>cn=Directory Manager</value>
+ </option>
+ <option>
+ <name>adminPassword</name>
+ <value>password</value>
+ </option>
+ <option>
+ <name>searchTimeLimit</name>
+ <value>10000</value>
+ </option>
+ </options>
+ </identity-store>
+ </identity-stores>
+ </stores>
+</jboss-identity>
\ No newline at end of file
Property changes on: trunk/identity-impl/src/test/resources/store-test-config.xml
___________________________________________________________________
Name: svn:mergeinfo
+
Modified: trunk/identity-spi/src/main/java/org/jboss/identity/spi/configuration/metadata/IdentityObjectTypeMetaData.java
===================================================================
--- trunk/identity-spi/src/main/java/org/jboss/identity/spi/configuration/metadata/IdentityObjectTypeMetaData.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-spi/src/main/java/org/jboss/identity/spi/configuration/metadata/IdentityObjectTypeMetaData.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -39,6 +39,8 @@
List<AttributeMetaData> getAttributes();
+ List<String> getCredentials();
+
Map<String, List<String>> getOptions();
List<String> getOption(String optionName);
Modified: trunk/identity-spi/src/main/java/org/jboss/identity/spi/credential/IdentityObjectCredential.java
===================================================================
--- trunk/identity-spi/src/main/java/org/jboss/identity/spi/credential/IdentityObjectCredential.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-spi/src/main/java/org/jboss/identity/spi/credential/IdentityObjectCredential.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -34,5 +34,18 @@
* @return
*/
IdentityObjectCredentialType getType();
-
+
+ /**
+ * @return Should return either String for text based credentials or byte[] for binary
+ */
+ Object getValue();
+
+
+ /**
+ * @return encoded value. For example hash from a string password.
+ * Should return either String for text based credentials or byte[] for binary.
+ * May return null if credential implementaion doesn't provide encoding mechanism.
+ * IdentityStore is not obligated to use encoded value.
+ */
+ Object getEncodedValue();
}
Modified: trunk/identity-spi/src/main/java/org/jboss/identity/spi/store/FeaturesMetaData.java
===================================================================
--- trunk/identity-spi/src/main/java/org/jboss/identity/spi/store/FeaturesMetaData.java 2008-11-18 21:49:18 UTC (rev 123)
+++ trunk/identity-spi/src/main/java/org/jboss/identity/spi/store/FeaturesMetaData.java 2008-12-02 18:51:34 UTC (rev 124)
@@ -55,7 +55,9 @@
*/
boolean isControlSupported(IdentityObjectType identityObjectType, Class controlClazz);
+ //TODO: isControlSupported per RelationshipType
+
/**
* @return set of identity types that can be persisted
*/
17 years, 7 months