07 Jul, 2014

1 commit


06 Jul, 2014

1 commit


01 Jul, 2014

1 commit


26 Jun, 2014

1 commit


25 Jun, 2014

1 commit

  • DAS now supports goto URL validation.
    Changes:
    * The valid goto URL domain setting has been moved to a new service called
    validationService, the new property name is
    "openam-auth-valid-goto-resources"
    * A new delegation policy has been created that allows agent accounts to
    read the validationService settings
    * The necessary upgrade step has been implemented that should migrate
    existing valid goto domains to the new service (also removes the old ones),
    which also ensures that the new delegation policy is added to the system.
    * The Goto URL validation logic has been extracted out to a separate class
    called GotoUrlValidator, which is now can be used from both openam-core
    and openam-federation-library (for Relaystate evaluations).
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@9424 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major
     

04 Jun, 2014

1 commit


13 May, 2014

3 commits


29 Apr, 2014

1 commit


15 Apr, 2014

1 commit


14 Apr, 2014

2 commits


02 Apr, 2014

1 commit

  • AttributeQueryUtil now utilizes the configured SP attribute mapper to map
    received attributes the same way as they would come as part of an
    assertion.
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@8561 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major
     

27 Mar, 2014

1 commit


23 Mar, 2014

1 commit


02 Mar, 2014

1 commit

  • Adding extra emptiness check to ensure we don't try to retrieve
    affiliationDescriptor for "".
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@8269 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major
     

26 Feb, 2014

1 commit


23 Feb, 2014

1 commit


20 Feb, 2014

2 commits


04 Feb, 2014

2 commits


07 Jan, 2014

2 commits


14 Dec, 2013

1 commit

  • Modified the NameIdentifierMapper interface so it now receives the
    NameIDFormat value directly instead of using a session property as
    transport.
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@7573 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major
     

06 Dec, 2013

1 commit


04 Dec, 2013

4 commits


21 Nov, 2013

1 commit


20 Nov, 2013

1 commit

  • For SAML logins the LoginServlet should detect the authentication session
    from the query string rather than using any existing cookies, that way we
    can make sure that the SAML authentication flow will stay on the server
    that stores the necessary request data to finish the SAML.
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@7351 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major
     

19 Nov, 2013

1 commit


13 Nov, 2013

4 commits

  • SP Adapter is now invoked when the IdP Proxy sends the proxied SAML
    request.
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@7280 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major
     
  • New extension point for IdPAdapter that makes it possible to modify the
    SAML response before it's sent out.
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@7278 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major
     
  • The SLO code has been adjusted to cope with situations of having different
    sets of supported SLO bindings, and also handle the case when there is no
    "appropriate" binding for the current SLO process.
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@7274 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major
     
  • The SP initiated SLO process has been modified to only try to send SLO
    request with the SP the session is currently associated with.
    Also made a small adjustment to the code so failing to invalidate the local
    session no longer results in a logout error.
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@7271 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major
     

11 Oct, 2013

1 commit


02 Oct, 2013

1 commit

  • This one turned out to be issue with the input data. The SAMLAdapter
    expected the expiration date in _seconds_, but instead milliseconds were
    provided, and this resulted in quite a time difference.
    
    git-svn-id: https://svn.forgerock.org/openam/trunk@6751 0f4defcf-c51a-4c67-9f44-6fb5eba73c5d
    peter.major