Permalink
Name already in use
A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
inc-meta/mdx/uk/check_uk_mdattr.xsl
Go to fileThis commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.

See ukf/ukf-meta#359 for details
144 lines (129 sloc)
5.27 KB
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<?xml version="1.0" encoding="UTF-8"?> | |
<!-- | |
check_uk_mdattr.xsl | |
UKf-specific check for appropriate entity attributes in fragment files. | |
Author: Ian A. Young <ian@iay.org.uk> | |
--> | |
<xsl:stylesheet version="1.0" | |
xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" | |
xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" | |
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" | |
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" | |
xmlns:xsl="http://www.w3.org/1999/XSL/Transform" | |
xmlns="urn:oasis:names:tc:SAML:2.0:metadata"> | |
<!-- | |
Common support functions. | |
--> | |
<xsl:import href="../_rules/check_framework.xsl"/> | |
<!-- | |
UKf doesn't register entity attributes using assertions. | |
--> | |
<xsl:template match="mdattr:EntityAttributes/saml:Assertion"> | |
<xsl:call-template name="error"> | |
<xsl:with-param name="m">Assertion not permitted within EntityAttributes</xsl:with-param> | |
</xsl:call-template> | |
</xsl:template> | |
<!-- | |
All entity attributes should have the standard SAML 2.0 URI name format. | |
--> | |
<xsl:template match="mdattr:EntityAttributes/saml:Attribute[not(@NameFormat)]"> | |
<xsl:call-template name="error"> | |
<xsl:with-param name="m"> | |
<xsl:text>entity attribute </xsl:text> | |
<xsl:value-of select="@Name"/> | |
<xsl:text> has no NameFormat attribute</xsl:text> | |
</xsl:with-param> | |
</xsl:call-template> | |
</xsl:template> | |
<xsl:template match="mdattr:EntityAttributes/saml:Attribute | |
[@NameFormat != 'urn:oasis:names:tc:SAML:2.0:attrname-format:uri']"> | |
<xsl:call-template name="error"> | |
<xsl:with-param name="m"> | |
<xsl:text>entity attribute </xsl:text> | |
<xsl:value-of select="@Name"/> | |
<xsl:text> has wrong NameFormat value </xsl:text> | |
<xsl:value-of select="@NameFormat"/> | |
</xsl:with-param> | |
</xsl:call-template> | |
</xsl:template> | |
<!-- | |
Validate attribute name. Each @Name permitted here should have a | |
corresponding attribute value validator below. | |
--> | |
<xsl:template match="mdattr:EntityAttributes/saml:Attribute | |
[@Name != 'http://macedir.org/entity-category'] | |
[@Name != 'http://macedir.org/entity-category-support'] | |
[@Name != 'urn:oasis:names:tc:SAML:attribute:assurance-certification'] | |
[@Name != 'urn:oasis:names:tc:SAML:profiles:subject-id:req'] | |
"> | |
<xsl:call-template name="error"> | |
<xsl:with-param name="m"> | |
<xsl:text>unknown entity attribute name </xsl:text> | |
<xsl:value-of select="@Name"/> | |
</xsl:with-param> | |
</xsl:call-template> | |
</xsl:template> | |
<!-- | |
Validate entity category values. | |
--> | |
<xsl:template match="mdattr:EntityAttributes/saml:Attribute[@Name='http://macedir.org/entity-category'] | |
/saml:AttributeValue | |
[. != 'http://refeds.org/category/hide-from-discovery'] | |
[. != 'http://refeds.org/category/research-and-scholarship'] | |
[. != 'http://www.geant.net/uri/dataprotection-code-of-conduct/v1'] | |
"> | |
<xsl:call-template name="error"> | |
<xsl:with-param name="m"> | |
<xsl:text>unknown entity category URI </xsl:text> | |
<xsl:value-of select="."/> | |
</xsl:with-param> | |
</xsl:call-template> | |
</xsl:template> | |
<!-- | |
Validate entity category support values. | |
--> | |
<xsl:template match="mdattr:EntityAttributes/saml:Attribute[@Name='http://macedir.org/entity-category-support'] | |
/saml:AttributeValue | |
[. != 'http://refeds.org/category/research-and-scholarship'] | |
[. != 'http://www.geant.net/uri/dataprotection-code-of-conduct/v1'] | |
[. != 'https://refeds.org/category/code-of-conduct/v2'] | |
"> | |
<xsl:call-template name="error"> | |
<xsl:with-param name="m"> | |
<xsl:text>unknown entity category support URI </xsl:text> | |
<xsl:value-of select="."/> | |
</xsl:with-param> | |
</xsl:call-template> | |
</xsl:template> | |
<!-- | |
Validate assurance certification values. | |
--> | |
<xsl:template match="mdattr:EntityAttributes/saml:Attribute[@Name='urn:oasis:names:tc:SAML:attribute:assurance-certification'] | |
/saml:AttributeValue | |
[. != 'https://refeds.org/sirtfi'] | |
"> | |
<xsl:call-template name="error"> | |
<xsl:with-param name="m"> | |
<xsl:text>unknown assurance certification URI </xsl:text> | |
<xsl:value-of select="."/> | |
</xsl:with-param> | |
</xsl:call-template> | |
</xsl:template> | |
<!-- | |
Validate SAML subject identifier requirement value. | |
--> | |
<xsl:template match="mdattr:EntityAttributes/saml:Attribute[@Name='urn:oasis:names:tc:SAML:profiles:subject-id:req'] | |
/saml:AttributeValue | |
[. != 'subject-id'] | |
[. != 'pairwise-id'] | |
[. != 'none'] | |
[. != 'any'] | |
"> | |
<xsl:call-template name="error"> | |
<xsl:with-param name="m"> | |
<xsl:text>unknown subject identifier requirement values </xsl:text> | |
<xsl:value-of select="."/> | |
</xsl:with-param> | |
</xsl:call-template> | |
</xsl:template> | |
</xsl:stylesheet> |