1
|
|
|
<?php |
2
|
|
|
|
3
|
|
|
namespace Kuleuven\AuthenticationBundle\DependencyInjection; |
4
|
|
|
|
5
|
|
|
use Symfony\Component\Config\Definition\Builder\TreeBuilder; |
6
|
|
|
use Symfony\Component\Config\Definition\ConfigurationInterface; |
7
|
|
|
|
8
|
|
|
class Configuration implements ConfigurationInterface |
9
|
|
|
{ |
10
|
|
|
/** |
11
|
|
|
* {@inheritdoc} |
12
|
|
|
*/ |
13
|
|
|
public function getConfigTreeBuilder() |
14
|
|
|
{ |
15
|
|
|
$treeBuilder = new TreeBuilder(); |
16
|
|
|
$rootNode = $treeBuilder->root('kuleuven_authentication'); |
17
|
|
|
|
18
|
|
|
/** @noinspection PhpUndefinedMethodInspection */ |
19
|
|
|
$rootNode |
20
|
|
|
->fixXmlConfig('attribute_definition') |
21
|
|
|
->fixXmlConfig('overwrite') |
22
|
|
|
->children() |
23
|
|
|
|
24
|
|
|
// Attribute definitions |
25
|
|
|
->arrayNode('authentication_attribute_definitions') |
26
|
|
|
->useAttributeAsKey('alias') |
27
|
|
|
->prototype('array') |
28
|
|
|
->children() |
29
|
|
|
->scalarNode('id')->isRequired()->end() |
30
|
|
|
->booleanNode('multivalue')->defaultFalse()->end() |
31
|
|
|
->scalarNode('charset')->defaultValue('UTF-8')->end() |
32
|
|
|
->end() |
33
|
|
|
->end() |
34
|
|
|
->end() |
35
|
|
|
|
36
|
|
|
// Attribute requirements |
37
|
|
|
->arrayNode('authentication_attribute_requirements') |
38
|
|
|
->useAttributeAsKey('name') |
39
|
|
|
->normalizeKeys(false) |
40
|
|
|
->prototype('scalar')->end() |
41
|
|
|
->defaultValue(['Shib-Identity-Provider' => 'urn:mace:kuleuven.be:kulassoc:kuleuven.be']) |
42
|
|
|
->end() |
43
|
|
|
|
44
|
|
|
// Attribute overwrites |
45
|
|
|
->booleanNode('authentication_attribute_overwrites_enabled')->defaultFalse()->end() |
46
|
|
|
->arrayNode('authentication_attribute_overwrites') |
47
|
|
|
->useAttributeAsKey('id') |
48
|
|
|
->normalizeKeys(false) |
49
|
|
|
->prototype('scalar')->end() |
50
|
|
|
->defaultValue([]) |
51
|
|
|
->end() |
52
|
|
|
|
53
|
|
|
// Attribute LDAP overwrites |
54
|
|
|
->booleanNode('authentication_attribute_ldap_enabled')->defaultFalse()->end() |
55
|
|
|
->arrayNode('authentication_attribute_ldap_filter') |
56
|
|
|
->useAttributeAsKey('id') |
57
|
|
|
->normalizeKeys(false) |
58
|
|
|
->prototype('scalar')->end() |
59
|
|
|
->defaultValue([]) |
60
|
|
|
->end() |
61
|
|
|
|
62
|
|
|
// Attribute header overwrites |
63
|
|
|
->booleanNode('authentication_attribute_headers_enabled')->defaultFalse()->end() |
64
|
|
|
|
65
|
|
|
// Shibboleth |
66
|
|
|
->booleanNode('shibboleth_is_secured_handler')->defaultTrue()->end() |
67
|
|
|
->scalarNode('shibboleth_handler_path')->defaultValue('/Shibboleth.sso')->end() |
68
|
|
|
->scalarNode('shibboleth_status_path')->defaultValue('/Status')->end() |
69
|
|
|
->scalarNode('shibboleth_session_login_path')->defaultValue('/Login')->end() |
70
|
|
|
->scalarNode('shibboleth_session_logout_path')->defaultValue('/Logout')->end() |
71
|
|
|
->scalarNode('shibboleth_session_logout_target')->defaultValue(null)->end() |
72
|
|
|
->scalarNode('shibboleth_session_overview_path')->defaultValue('/Session')->end() |
73
|
|
|
->scalarNode('shibboleth_username_attribute')->defaultValue('Shib-Person-uid')->end() |
74
|
|
|
->scalarNode('shibboleth_authenticated_attribute')->defaultValue('Shib-Identity-Provider')->end() |
75
|
|
|
->scalarNode('shibboleth_logout_url_attribute')->defaultValue('Shib-logoutURL')->end() |
76
|
|
|
->scalarNode('shibboleth_default_charset')->defaultValue('ISO-8859-1')->end() |
77
|
|
|
|
78
|
|
|
// LDAP |
79
|
|
|
->scalarNode('ldap_rdn')->defaultValue('')->end() |
80
|
|
|
->scalarNode('ldap_password')->defaultValue('')->end() |
81
|
|
|
->scalarNode('ldap_base')->defaultValue('ou=people,dc=kuleuven,dc=be')->end() |
82
|
|
|
->scalarNode('ldap_domain')->defaultValue('ldap.kuleuven.be')->cannotBeEmpty()->end() |
83
|
|
|
->scalarNode('ldap_port')->defaultValue('389')->end() |
84
|
|
|
->enumNode('ldap_encryption')->values(['none', 'ssl', 'tls'])->defaultValue('none')->end() |
85
|
|
|
->booleanNode('ldap_referrals')->defaultFalse()->end() |
86
|
|
|
->booleanNode('ldap_version')->defaultValue('3')->end() |
87
|
|
|
->booleanNode('ldap_debug')->defaultFalse()->end() |
88
|
|
|
|
89
|
|
|
// Person Data API |
90
|
|
|
->scalarNode('person_data_api_url')->defaultValue('https://webwsp.aps.kuleuven.be/esap/public/odata/sap/zh_person_srv/Persons(\'%s\')?$format=json&$expand=WorkAddresses')->end() |
91
|
|
|
|
92
|
|
|
->end(); |
93
|
|
|
|
94
|
|
|
return $treeBuilder; |
95
|
|
|
} |
96
|
|
|
} |
97
|
|
|
|