mirror of
https://git.anonymousland.org/anonymousland/synapse-product.git
synced 2025-01-12 14:59:30 -05:00
c7401a697f
This implements both a SAML2 metadata endpoint (at `/_matrix/saml2/metadata.xml`), and a SAML2 response receiver (at `/_matrix/saml2/authn_response`). If the SAML2 response matches what's been configured, we complete the SSO login flow by redirecting to the client url (aka `RelayState` in SAML2 jargon) with a login token. What we don't yet have is anything to build a SAML2 request and redirect the user to the identity provider. That is left as an exercise for the reader.
37 lines
1.1 KiB
Python
37 lines
1.1 KiB
Python
# -*- coding: utf-8 -*-
|
|
# Copyright 2018 New Vector Ltd
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
|
|
import saml2.metadata
|
|
|
|
from twisted.web.resource import Resource
|
|
|
|
|
|
class SAML2MetadataResource(Resource):
|
|
"""A Twisted web resource which renders the SAML metadata"""
|
|
|
|
isLeaf = 1
|
|
|
|
def __init__(self, hs):
|
|
Resource.__init__(self)
|
|
self.sp_config = hs.config.saml2_sp_config
|
|
|
|
def render_GET(self, request):
|
|
metadata_xml = saml2.metadata.create_metadata_string(
|
|
configfile=None, config=self.sp_config,
|
|
)
|
|
request.setHeader(b"Content-Type", b"text/xml; charset=utf-8")
|
|
return metadata_xml
|