Problem/Motivation

I need to add to my request SAML a specific AuthnContextClassRef with Comparison set to minimum.

Something like:

<samlp:RequestedAuthnContext Comparison="minimum">
  <saml:AuthnContextClassRef>
    urn:qoa.my.custom.namespace:names:tc:ac:classes:20
  </saml:AuthnContextClassRef>
</samlp:RequestedAuthnContext>

Proposed resolution

I don't think it's a good idea to try to add an UI for this kind of use case but it would be nice if the plugin add an extension point to let developer set pass/override custom settings to the underlying SAML library.

I don't have the full overview of the module but I suspect a good candidate is to hook into Drupal\samlauth\SamlService::getSamlAuth($purpose = '', $initialize = TRUE).

As I need this quickly, I will propose a patch and we can start the discussion on it.

Issue fork samlauth-3553986

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

gido created an issue. See original summary.

wengerk’s picture

Status: Active » Needs review

Looks good to me!

One alternative approach to consider would be implementing an OOP Hook Alter (see https://www.drupal.org/node/3442349). However, from my perspective, using an event subscriber versus a hook implementation are functionally equivalent for this use case, so either approach works well.

roderik made their first commit to this issue’s fork.

roderik’s picture

Status: Needs review » Reviewed & tested by the community

Thank you for a very complete MR (with README, comments and tests).

I don't have a strong opinion about OOP hooks vs event subscribers. I'll likely start switching back to using OOP hooks more, in general... but since this module doesn't use them yet and the hook isn't going to be super commonly used... no reason for me to change the MR.

The only thing I've done is change the assertion messages to be consistent with what's being done in this module. (They are technically 'error mesages', and IMHO should not say "X happened" on an assertion that X happened -> are printed when _did not_ happen).
...plus sneak in a fix to a PHPunit deprecation warning that just popped up in Gitlab...

  • roderik committed 14ccf32f on 8.x-3.x authored by gido
    feat: #3553986 Add Event to alter OneLogin SAML configuration before...
roderik’s picture

Status: Reviewed & tested by the community » Fixed

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.