2019-11-17 08:26:43 -05:00
|
|
|
<?php
|
|
|
|
|
2023-05-17 12:56:55 -04:00
|
|
|
namespace BookStack\Access\Controllers;
|
2019-11-17 08:26:43 -05:00
|
|
|
|
2023-05-17 12:56:55 -04:00
|
|
|
use BookStack\Access\Saml2Service;
|
2023-05-18 15:53:39 -04:00
|
|
|
use BookStack\Http\Controller;
|
2021-10-20 08:30:45 -04:00
|
|
|
use Illuminate\Http\Request;
|
2021-11-14 16:13:24 -05:00
|
|
|
use Illuminate\Support\Str;
|
2019-11-17 08:26:43 -05:00
|
|
|
|
|
|
|
class Saml2Controller extends Controller
|
|
|
|
{
|
2022-09-22 11:54:27 -04:00
|
|
|
protected Saml2Service $samlService;
|
2019-11-17 08:26:43 -05:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Saml2Controller constructor.
|
|
|
|
*/
|
|
|
|
public function __construct(Saml2Service $samlService)
|
|
|
|
{
|
|
|
|
$this->samlService = $samlService;
|
2020-02-02 08:10:21 -05:00
|
|
|
$this->middleware('guard:saml2');
|
2019-11-17 08:26:43 -05:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Start the login flow via SAML2.
|
|
|
|
*/
|
|
|
|
public function login()
|
|
|
|
{
|
|
|
|
$loginDetails = $this->samlService->login();
|
|
|
|
session()->flash('saml2_request_id', $loginDetails['id']);
|
|
|
|
|
|
|
|
return redirect($loginDetails['url']);
|
|
|
|
}
|
|
|
|
|
2019-11-17 10:40:36 -05:00
|
|
|
/**
|
|
|
|
* Start the logout flow via SAML2.
|
|
|
|
*/
|
|
|
|
public function logout()
|
|
|
|
{
|
2021-10-23 12:26:01 -04:00
|
|
|
$logoutDetails = $this->samlService->logout(auth()->user());
|
2019-11-17 10:40:36 -05:00
|
|
|
|
|
|
|
if ($logoutDetails['id']) {
|
|
|
|
session()->flash('saml2_logout_request_id', $logoutDetails['id']);
|
|
|
|
}
|
|
|
|
|
|
|
|
return redirect($logoutDetails['url']);
|
|
|
|
}
|
|
|
|
|
2019-11-17 08:26:43 -05:00
|
|
|
/*
|
|
|
|
* Get the metadata for this SAML2 service provider.
|
|
|
|
*/
|
|
|
|
public function metadata()
|
|
|
|
{
|
|
|
|
$metaData = $this->samlService->metadata();
|
2021-06-26 11:23:15 -04:00
|
|
|
|
2019-11-17 08:26:43 -05:00
|
|
|
return response()->make($metaData, 200, [
|
2021-06-26 11:23:15 -04:00
|
|
|
'Content-Type' => 'text/xml',
|
2019-11-17 08:26:43 -05:00
|
|
|
]);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Single logout service.
|
|
|
|
* Handle logout requests and responses.
|
|
|
|
*/
|
|
|
|
public function sls()
|
|
|
|
{
|
2019-11-17 10:40:36 -05:00
|
|
|
$requestId = session()->pull('saml2_logout_request_id', null);
|
|
|
|
$redirect = $this->samlService->processSlsResponse($requestId) ?? '/';
|
2021-06-26 11:23:15 -04:00
|
|
|
|
2019-11-17 10:40:36 -05:00
|
|
|
return redirect($redirect);
|
2019-11-17 08:26:43 -05:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2021-10-20 08:30:45 -04:00
|
|
|
* Assertion Consumer Service start URL. Takes the SAMLResponse from the IDP.
|
|
|
|
* Due to being an external POST request, we likely won't have context of the
|
|
|
|
* current user session due to lax cookies. To work around this we store the
|
|
|
|
* SAMLResponse data and redirect to the processAcs endpoint for the actual
|
|
|
|
* processing of the request with proper context of the user session.
|
2019-11-17 08:26:43 -05:00
|
|
|
*/
|
2021-10-20 08:30:45 -04:00
|
|
|
public function startAcs(Request $request)
|
2019-11-17 08:26:43 -05:00
|
|
|
{
|
2021-10-20 08:30:45 -04:00
|
|
|
$samlResponse = $request->get('SAMLResponse', null);
|
|
|
|
|
|
|
|
if (empty($samlResponse)) {
|
|
|
|
$this->showErrorNotification(trans('errors.saml_fail_authed', ['system' => config('saml2.name')]));
|
2021-10-20 08:40:27 -04:00
|
|
|
|
2021-10-20 08:30:45 -04:00
|
|
|
return redirect('/login');
|
|
|
|
}
|
|
|
|
|
|
|
|
$acsId = Str::random(16);
|
|
|
|
$cacheKey = 'saml2_acs:' . $acsId;
|
|
|
|
cache()->set($cacheKey, encrypt($samlResponse), 10);
|
|
|
|
|
|
|
|
return redirect()->guest('/saml2/acs?id=' . $acsId);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Assertion Consumer Service process endpoint.
|
|
|
|
* Processes the SAML response from the IDP with context of the current session.
|
|
|
|
* Takes the SAML request from the cache, added by the startAcs method above.
|
|
|
|
*/
|
|
|
|
public function processAcs(Request $request)
|
|
|
|
{
|
|
|
|
$acsId = $request->get('id', null);
|
|
|
|
$cacheKey = 'saml2_acs:' . $acsId;
|
|
|
|
$samlResponse = null;
|
2021-10-20 08:40:27 -04:00
|
|
|
|
2021-10-20 08:30:45 -04:00
|
|
|
try {
|
|
|
|
$samlResponse = decrypt(cache()->pull($cacheKey));
|
2021-10-20 08:40:27 -04:00
|
|
|
} catch (\Exception $exception) {
|
|
|
|
}
|
2021-11-14 16:13:24 -05:00
|
|
|
$requestId = session()->pull('saml2_request_id', null);
|
2021-10-20 08:30:45 -04:00
|
|
|
|
|
|
|
if (empty($acsId) || empty($samlResponse)) {
|
2019-11-17 08:26:43 -05:00
|
|
|
$this->showErrorNotification(trans('errors.saml_fail_authed', ['system' => config('saml2.name')]));
|
2021-10-20 08:40:27 -04:00
|
|
|
|
2021-10-20 08:30:45 -04:00
|
|
|
return redirect('/login');
|
|
|
|
}
|
2021-06-26 11:23:15 -04:00
|
|
|
|
2021-10-20 08:30:45 -04:00
|
|
|
$user = $this->samlService->processAcsResponse($requestId, $samlResponse);
|
|
|
|
if (is_null($user)) {
|
|
|
|
$this->showErrorNotification(trans('errors.saml_fail_authed', ['system' => config('saml2.name')]));
|
2021-10-20 08:40:27 -04:00
|
|
|
|
2019-11-17 08:26:43 -05:00
|
|
|
return redirect('/login');
|
|
|
|
}
|
|
|
|
|
|
|
|
return redirect()->intended();
|
|
|
|
}
|
|
|
|
}
|