"Fossies" - the Fresh Open Source Software Archive  

Source code changes of the file "keystone/api/_shared/saml.py" between
keystone-16.0.1.tar.gz and keystone-17.0.0.tar.gz

About: OpenStack Keystone (Core Service: Identity) provides an authentication and authorization service for other OpenStack services. Provides a catalog of endpoints for all OpenStack services.
The "Ussuri" series (latest release).

saml.py  (keystone-16.0.1):saml.py  (keystone-17.0.0)
skipping to change at line 13 skipping to change at line 13
# a copy of the License at # a copy of the License at
# #
# http://www.apache.org/licenses/LICENSE-2.0 # http://www.apache.org/licenses/LICENSE-2.0
# #
# Unless required by applicable law or agreed to in writing, software # Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT # distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the # WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations # License for the specific language governing permissions and limitations
# under the License. # under the License.
from oslo_serialization import jsonutils
from keystone.common import provider_api from keystone.common import provider_api
import keystone.conf import keystone.conf
from keystone import exception from keystone import exception
from keystone.federation import idp as keystone_idp from keystone.federation import idp as keystone_idp
from keystone.federation import utils as federation_utils from keystone.federation import utils as federation_utils
from keystone.i18n import _ from keystone.i18n import _
CONF = keystone.conf.CONF CONF = keystone.conf.CONF
PROVIDERS = provider_api.ProviderAPIs PROVIDERS = provider_api.ProviderAPIs
skipping to change at line 48 skipping to change at line 50
subject = token.user['name'] subject = token.user['name']
role_names = [] role_names = []
for role in token.roles: for role in token.roles:
role_names.append(role['name']) role_names.append(role['name'])
project = token.project['name'] project = token.project['name']
# NOTE(rodrigods): the domain name is necessary in order to distinguish # NOTE(rodrigods): the domain name is necessary in order to distinguish
# between projects and users with the same name in different domains. # between projects and users with the same name in different domains.
project_domain_name = token.project_domain['name'] project_domain_name = token.project_domain['name']
subject_domain_name = token.user_domain['name'] subject_domain_name = token.user_domain['name']
def group_membership():
"""Return a list of dictionaries serialized as strings.
The expected return structure is::
['JSON:{"name":"group1","domain":{"name":"Default"}}',
'JSON:{"name":"group2","domain":{"name":"Default"}}']
"""
user_groups = []
groups = PROVIDERS.identity_api.list_groups_for_user(
token.user_id)
for group in groups:
user_group = {}
group_domain_name = PROVIDERS.resource_api.get_domain(
group['domain_id'])['name']
user_group["name"] = group['name']
user_group["domain"] = {'name': group_domain_name}
user_groups.append('JSON:' + jsonutils.dumps(user_group))
return user_groups
groups = group_membership()
generator = keystone_idp.SAMLGenerator() generator = keystone_idp.SAMLGenerator()
response = generator.samlize_token( response = generator.samlize_token(
issuer, sp_url, subject, subject_domain_name, issuer, sp_url, subject, subject_domain_name,
role_names, project, project_domain_name) role_names, project, project_domain_name, groups)
return response, service_provider return response, service_provider
 End of changes. 3 change blocks. 
1 lines changed or deleted 23 lines changed or added

Home  |  About  |  Features  |  All  |  Newest  |  Dox  |  Diffs  |  RSS Feeds  |  Screenshots  |  Comments  |  Imprint  |  Privacy  |  HTTP(S)