3 # Copyright (C) 2014 Simo Sorce <simo@redhat.com>
5 # see file 'COPYING' for use and warranty information
7 # This program is free software; you can redistribute it and/or modify
8 # it under the terms of the GNU General Public License as published by
9 # the Free Software Foundation, either version 3 of the License, or
10 # (at your option) any later version.
12 # This program is distributed in the hope that it will be useful,
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 # GNU General Public License for more details.
17 # You should have received a copy of the GNU General Public License
18 # along with this program. If not, see <http://www.gnu.org/licenses/>.
27 class WrongPage(Exception):
31 class PageTree(object):
33 def __init__(self, result):
35 self.text = result.text
41 self._tree = html.fromstring(self.text)
44 def first_value(self, rule):
45 result = self.tree.xpath(rule)
46 if type(result) is list:
53 def all_values(self, rule):
54 result = self.tree.xpath(rule)
55 if type(result) is list:
59 def make_referer(self):
60 return self.result.url
62 def expected_value(self, rule, expected):
63 value = self.first_value(rule)
65 raise ValueError("Expected [%s], got [%s]" % (expected, value))
68 class HttpSessions(object):
73 def add_server(self, name, baseuri, user=None, pwd=None):
74 new = {'baseuri': baseuri,
75 'session': requests.Session()}
80 self.servers[name] = new
82 def get_session(self, url):
83 for srv in self.servers:
85 if url.startswith(d['baseuri']):
88 raise ValueError("Unknown URL: %s" % url)
90 def get(self, url, **kwargs):
91 session = self.get_session(url)
92 return session.get(url, allow_redirects=False, **kwargs)
94 def post(self, url, **kwargs):
95 session = self.get_session(url)
96 return session.post(url, allow_redirects=False, **kwargs)
98 def access(self, action, url, **kwargs):
99 action = string.lower(action)
101 return self.get(url, **kwargs)
102 elif action == 'post':
103 return self.post(url, **kwargs)
105 raise ValueError("Unknown action type: [%s]" % action)
107 def new_url(self, referer, action):
108 if action.startswith('/'):
109 u = urlparse.urlparse(referer)
110 return '%s://%s%s' % (u.scheme, u.netloc, action)
113 def get_form_data(self, page, form_id, input_fields):
115 action = page.first_value('//form[@id="%s"]/@action' % form_id)
116 values.append(action)
117 method = page.first_value('//form[@id="%s"]/@method' % form_id)
118 values.append(method)
119 for field in input_fields:
120 value = page.all_values('//form[@id="%s"]/input/@%s' % (form_id,
125 def handle_login_form(self, idp, page):
126 if type(page) != PageTree:
127 raise TypeError("Expected PageTree object")
129 srv = self.servers[idp]
132 results = self.get_form_data(page, "login_form", [])
133 action_url = results[0]
135 if action_url is None:
137 except Exception: # pylint: disable=broad-except
138 raise WrongPage("Not a Login Form Page")
140 referer = page.make_referer()
141 headers = {'referer': referer}
142 payload = {'login_name': srv['user'],
143 'login_password': srv['pwd']}
145 return [method, self.new_url(referer, action_url),
146 {'headers': headers, 'data': payload}]
148 def handle_return_form(self, page):
149 if type(page) != PageTree:
150 raise TypeError("Expected PageTree object")
153 results = self.get_form_data(page, "saml-response",
155 action_url = results[0]
156 if action_url is None:
161 except Exception: # pylint: disable=broad-except
162 raise WrongPage("Not a Return Form Page")
164 referer = page.make_referer()
165 headers = {'referer': referer}
168 for i in range(0, len(names)):
169 payload[names[i]] = values[i]
171 return [method, self.new_url(referer, action_url),
172 {'headers': headers, 'data': payload}]
174 def fetch_page(self, idp, target_url):
180 r = self.access(action, url, **args) # pylint: disable=star-args
181 if r.status_code == 303:
182 url = r.headers['location']
185 elif r.status_code == 200:
189 (action, url, args) = self.handle_login_form(idp, page)
195 (action, url, args) = self.handle_return_form(page)
200 # Either we got what we wanted, or we have to stop anyway
203 raise ValueError("Unhandled status (%d) on url %s" % (
206 def auth_to_idp(self, idp):
208 srv = self.servers[idp]
209 target_url = '%s/%s/' % (srv['baseuri'], idp)
211 r = self.access('get', target_url)
212 if r.status_code != 200:
213 raise ValueError("Access to idp failed: %s" % repr(r))
216 page.expected_value('//div[@id="content"]/p/a/text()', 'Log In')
217 href = page.first_value('//div[@id="content"]/p/a/@href')
218 url = self.new_url(target_url, href)
220 page = self.fetch_page(idp, url)
221 page.expected_value('//div[@id="welcome"]/p/text()',
222 'Welcome %s!' % srv['user'])
224 def add_sp_metadata(self, idp, sp):
225 idpsrv = self.servers[idp]
226 idpuri = idpsrv['baseuri']
227 spuri = self.servers[sp]['baseuri']
229 url = '%s/%s/admin/providers/saml2/admin/new' % (idpuri, idp)
230 headers = {'referer': url}
231 payload = {'name': sp}
232 m = requests.get('%s/saml2/metadata' % spuri)
233 metafile = {'metafile': m.content}
234 r = idpsrv['session'].post(url, headers=headers,
235 data=payload, files=metafile)
236 if r.status_code != 200:
237 raise ValueError('Failed to post SP data [%s]' % repr(r))
240 page.expected_value('//div[@class="alert alert-success"]/p/text()',
241 'SP Successfully added')