Simplify saml validation
Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
@@ -23,15 +23,6 @@ import (
|
|||||||
pemutil "github.com/getprobo/probo/pkg/crypto/pem"
|
pemutil "github.com/getprobo/probo/pkg/crypto/pem"
|
||||||
)
|
)
|
||||||
|
|
||||||
type ValidationError struct {
|
|
||||||
Field string
|
|
||||||
Message string
|
|
||||||
}
|
|
||||||
|
|
||||||
func (e ValidationError) Error() string {
|
|
||||||
return fmt.Sprintf("%s: %s", e.Field, e.Message)
|
|
||||||
}
|
|
||||||
|
|
||||||
// ValidateIdPConfiguration validates only the IdP (Identity Provider) configuration.
|
// ValidateIdPConfiguration validates only the IdP (Identity Provider) configuration.
|
||||||
// This validates user-provided data from the IdP.
|
// This validates user-provided data from the IdP.
|
||||||
// SP (Service Provider) configuration is generated by the application and doesn't need validation.
|
// SP (Service Provider) configuration is generated by the application and doesn't need validation.
|
||||||
@@ -39,68 +30,45 @@ func ValidateIdPConfiguration(
|
|||||||
idpEntityID string,
|
idpEntityID string,
|
||||||
idpSsoURL string,
|
idpSsoURL string,
|
||||||
idpCertificate string,
|
idpCertificate string,
|
||||||
) []ValidationError {
|
) error {
|
||||||
var errors []ValidationError
|
|
||||||
|
|
||||||
// Validate IdP Entity ID
|
// Validate IdP Entity ID
|
||||||
if idpEntityID == "" {
|
if idpEntityID == "" {
|
||||||
errors = append(errors, ValidationError{
|
return fmt.Errorf("IdP Entity ID cannot be empty")
|
||||||
Field: "idp_entity_id",
|
|
||||||
Message: "IdP Entity ID cannot be empty",
|
|
||||||
})
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Validate IdP SSO URL - accept both HTTP and HTTPS
|
// Validate IdP SSO URL - accept both HTTP and HTTPS
|
||||||
if err := validateURL(idpSsoURL, "idp_sso_url"); err != nil {
|
if err := validateURL(idpSsoURL); err != nil {
|
||||||
errors = append(errors, *err)
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
// Validate IdP certificate
|
// Validate IdP certificate
|
||||||
if err := validateCertificate(idpCertificate); err != nil {
|
if err := validateCertificate(idpCertificate); err != nil {
|
||||||
errors = append(errors, ValidationError{
|
return err
|
||||||
Field: "idp_certificate",
|
|
||||||
Message: err.Error(),
|
|
||||||
})
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return errors
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func validateURL(urlStr string, fieldName string) *ValidationError {
|
func validateURL(urlStr string) error {
|
||||||
if urlStr == "" {
|
if urlStr == "" {
|
||||||
return &ValidationError{
|
return fmt.Errorf("URL cannot be empty")
|
||||||
Field: fieldName,
|
|
||||||
Message: "URL cannot be empty",
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
parsedURL, err := url.Parse(urlStr)
|
parsedURL, err := url.Parse(urlStr)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return &ValidationError{
|
return fmt.Errorf("invalid URL format: %w", err)
|
||||||
Field: fieldName,
|
|
||||||
Message: fmt.Sprintf("invalid URL format: %v", err),
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if parsedURL.Scheme == "" {
|
if parsedURL.Scheme == "" {
|
||||||
return &ValidationError{
|
return fmt.Errorf("URL must have a scheme (http or https)")
|
||||||
Field: fieldName,
|
|
||||||
Message: "URL must have a scheme (http or https)",
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if parsedURL.Scheme != "http" && parsedURL.Scheme != "https" {
|
if parsedURL.Scheme != "http" && parsedURL.Scheme != "https" {
|
||||||
return &ValidationError{
|
return fmt.Errorf("URL scheme must be http or https (found: %s)", parsedURL.Scheme)
|
||||||
Field: fieldName,
|
|
||||||
Message: "URL scheme must be http or https (found: " + parsedURL.Scheme + ")",
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if parsedURL.Host == "" {
|
if parsedURL.Host == "" {
|
||||||
return &ValidationError{
|
return fmt.Errorf("URL must have a host")
|
||||||
Field: fieldName,
|
|
||||||
Message: "URL must have a host",
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return nil
|
return nil
|
||||||
|
|||||||
Reference in New Issue
Block a user