From 9acbd575de83780c918f94455c7f876eeb688262 Mon Sep 17 00:00:00 2001 From: Kay Joosten Date: Mon, 20 Jul 2026 15:56:41 +0200 Subject: [PATCH] Remove guest_qualifier / isMemberOf guest-status feature Why is this change needed? Prior to this change, EngineBlock had a legacy feature (AddGuestStatus, FilterReservedMemberOfValues, coin:guest_qualifier) that added a reserved urn:collab:org value to isMemberOf based on an IdP's guest_qualifier setting, so SPs could tell full members from guests. The feature was confirmed unused (FCCN, the only suspected consumer, does not use it), is complex and non-obvious for deployers to configure, and is implemented in legacy Corto filter command code. How does it address the issue? Removes the AddGuestStatus and FilterReservedMemberOfValues filter commands from the input filter chain, the guestQualifier coin from Coins/IdentityProvider/PushMetadataAssembler/CortoDisassembler, the addgueststatus_guestqualifier parameter, related docs, and all test fixtures/assertions referencing guest_qualifier. https://github.com/OpenConext/OpenConext-engineblock/issues/1294 --- CHANGELOG.md | 6 + config/packages/parameters.yml.dist | 2 - docs/filter_commands.md | 22 ---- .../EngineBlock/Application/DiContainer.php | 8 -- .../Corto/Filter/Command/AddGuestStatus.php | 109 ------------------ .../Command/FilterReservedMemberOfValues.php | 64 ---------- library/EngineBlock/Corto/Filter/Input.php | 7 -- src/OpenConext/EngineBlock/Metadata/Coins.php | 8 -- .../Assembler/PushMetadataAssembler.php | 1 - .../Entity/Disassembler/CortoDisassembler.php | 2 - .../Metadata/Entity/IdentityProvider.php | 17 --- .../Stepup/StepupEntityFactory.php | 3 +- .../Api/ConnectionsControllerTest.php | 2 - .../Assembler/PushMetadataAssemblerTest.php | 17 --- .../fixtures/metadata_coin_collab.json | 4 +- .../fixtures/metadata_idp_display_data.json | 4 +- .../metadata_without_discoveries.json | 4 +- tests/resources/serviceregistry/idpList.php | 3 - .../Disassembler/CortoDisassemblerTest.php | 1 - 19 files changed, 10 insertions(+), 274 deletions(-) delete mode 100644 library/EngineBlock/Corto/Filter/Command/AddGuestStatus.php delete mode 100644 library/EngineBlock/Corto/Filter/Command/FilterReservedMemberOfValues.php diff --git a/CHANGELOG.md b/CHANGELOG.md index e82ba79038..cceb92ff4e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,12 @@ More information about our release strategy can be found in the [Development Guidelines](https://github.com/OpenConext/OpenConext-engineblock/wiki/Development-Guidelines#release-notes) on the EngineBlock wiki. +## Unreleased + +Removed: + +* Removed the guest_qualifier / isMemberOf guest-status feature (`AddGuestStatus`, `FilterReservedMemberOfValues`). Unused and confirmed safe to remove. (#1294) + ## 7.2.0 Maintenance: diff --git a/config/packages/parameters.yml.dist b/config/packages/parameters.yml.dist index 18212e78e5..da4509d200 100644 --- a/config/packages/parameters.yml.dist +++ b/config/packages/parameters.yml.dist @@ -144,8 +144,6 @@ parameters: engineblock.metadata_push_memory_limit: 256M ## Minimum execution time in milliseconds when a received response is deemed invalid (default: 5000 ms) minimum_execution_time_on_invalid_received_response: 5000 - ## The value for guest qualifier. Can be overridden for specific environments - addgueststatus_guestqualifier: 'urn:collab:org:dev.openconext.local' ## Language cookie settings ## The value for the domain is also used for clearing SSO Notification cookies if the feature is enabled diff --git a/docs/filter_commands.md b/docs/filter_commands.md index 3ba4328606..f434e21b6a 100644 --- a/docs/filter_commands.md +++ b/docs/filter_commands.md @@ -79,15 +79,6 @@ Uses: Modifies: - responseAttributes -### FilterReservedMemberOfValues -Removes any attributes starting with `urn:collab:org` as these may only be set by EngineBlock - -Uses: -- responseAttributes - -Modifies: -- responseAttributes - ### RunAttributeManipulations (for IdP) run possible custom attribute manipulations @@ -148,19 +139,6 @@ Uses: Modifies: - responseAttributes -### AddGuestStatus -Add the 'urn:collab:org:surf.nl' value to the isMemberOf attribute in case a user is considered a 'full member' of the -SURFfederation based on user and configuration - -Depends On: -- Configuration - -Uses: -- OpenConext\EngineBlock\Metadata\Entity\IdentityProvider - -Modifies: -- responseAttributes - ### ProvisionUser If a new user is encountered, provision the user in the UserDirectory, generating a CollabPersonId for new users. If an existing user is encountered, retrieve the stored CollabPersonId diff --git a/library/EngineBlock/Application/DiContainer.php b/library/EngineBlock/Application/DiContainer.php index e50237e2e4..ff17a63a78 100644 --- a/library/EngineBlock/Application/DiContainer.php +++ b/library/EngineBlock/Application/DiContainer.php @@ -487,14 +487,6 @@ public function getMfaHelper(): MfaHelperInterface return $this->container->get(\OpenConext\EngineBlock\Service\MfaHelper::class); } - /** - * @return string - */ - public function getGuestStatusQualifier() - { - return (string) $this->container->getParameter('addgueststatus_guestqualifier'); - } - /** * @return string */ diff --git a/library/EngineBlock/Corto/Filter/Command/AddGuestStatus.php b/library/EngineBlock/Corto/Filter/Command/AddGuestStatus.php deleted file mode 100644 index 455d86347e..0000000000 --- a/library/EngineBlock/Corto/Filter/Command/AddGuestStatus.php +++ /dev/null @@ -1,109 +0,0 @@ -_responseAttributes; - } - - public function execute() - { - // Is a guest user? - $this->_addIsMemberOfSurfNlAttribute(); - } - - /** - * Add the 'urn:collab:org:surf.nl' value to the isMemberOf attribute in case a user - * is considered a 'full member' of the SURFfederation. - * - * @return array Response Attributes - */ - protected function _addIsMemberOfSurfNlAttribute() - { - if ($this->_identityProvider->getCoins()->guestQualifier() === IdentityProvider::GUEST_QUALIFIER_ALL) { - // All users from this IdP are guests, so no need to add the isMemberOf - return; - } - - if ($this->_identityProvider->getCoins()->guestQualifier() === IdentityProvider::GUEST_QUALIFIER_NONE) { - $this->_setIsMember(); - return; - } - - $log = EngineBlock_ApplicationSingleton::getLog(); - if ($this->_identityProvider->getCoins()->guestQualifier() === IdentityProvider::GUEST_QUALIFIER_SOME) { - if (isset($this->_responseAttributes[static::URN_SURF_PERSON_AFFILIATION][0])) { - if ($this->_responseAttributes[static::URN_SURF_PERSON_AFFILIATION][0] === 'member') { - $this->_setIsMember(); - } - else { - $log->notice( - "Idp guestQualifier is set to 'Some', surfPersonAffiliation attribute does not contain " . - 'the value "member", so not adding isMemberOf for surf.nl' - ); - } - } - else { - $log->warning( - "Idp guestQualifier is set to 'Some' however, ". - "the surfPersonAffiliation attribute was not provided, " . - "not adding the isMemberOf for surf.nl", - array( - 'idp' => $this->_identityProvider, - 'response_attributes' => $this->_responseAttributes, - ) - ); - } - return; - } - - // Unknown policy for handling guests? Treat the user as a guest, but issue a warning in the logs - $log->warning( - "Idp guestQualifier is set to unknown value '{$this->_identityProvider['GuestQualifier']}", - array( - 'idp' => $this->_identityProvider, - 'response_attributes' => $this->_responseAttributes, - ) - ); - } - - protected function _setIsMember() - { - if (!isset($this->_responseAttributes[static::URN_IS_MEMBER_OF])) { - $this->_responseAttributes[static::URN_IS_MEMBER_OF] = array(); - } - - $qualifier = EngineBlock_ApplicationSingleton::getInstance()->getDiContainer() - ->getGuestStatusQualifier(); - $this->_responseAttributes[static::URN_IS_MEMBER_OF][] = $qualifier; - } -} diff --git a/library/EngineBlock/Corto/Filter/Command/FilterReservedMemberOfValues.php b/library/EngineBlock/Corto/Filter/Command/FilterReservedMemberOfValues.php deleted file mode 100644 index 6e83da34e5..0000000000 --- a/library/EngineBlock/Corto/Filter/Command/FilterReservedMemberOfValues.php +++ /dev/null @@ -1,64 +0,0 @@ -_responseAttributes; - } - - public function execute() - { - if (!isset($this->_responseAttributes[self::URN_IS_MEMBER_OF])) { - return; - } - - $groups = &$this->_responseAttributes[self::URN_IS_MEMBER_OF]; - $gcount = count($groups); - - for ($i = 0; $i < $gcount; $i++) { - $hasVoPrefix = strpos($groups[$i], self::URN_COLLAB_ORG_PREFIX) === 0; - - if (!$hasVoPrefix) { - continue; - } - - unset($groups[$i]); - - EngineBlock_ApplicationSingleton::getLog()->notice( - sprintf( - 'FilterReservedMemberOfValue: Removed "%s" value from %s attribute by %s', - $groups[$i], - self::URN_IS_MEMBER_OF, - $this->_identityProvider->entityId - ) - ); - } - } -} diff --git a/library/EngineBlock/Corto/Filter/Input.php b/library/EngineBlock/Corto/Filter/Input.php index a399f3f92b..7d94c9ca34 100644 --- a/library/EngineBlock/Corto/Filter/Input.php +++ b/library/EngineBlock/Corto/Filter/Input.php @@ -57,10 +57,6 @@ public function getCommands() // Convert all OID attributes to URN and remove the OID variant new EngineBlock_Corto_Filter_Command_NormalizeAttributes(), - // The IdP is not allowed to set the isMemberOf attribute with urn:collab:org groups - // so we make sure to remove them - new EngineBlock_Corto_Filter_Command_FilterReservedMemberOfValues(), - // Run custom attribute manipulations new EngineBlock_Corto_Filter_Command_RunAttributeManipulations( EngineBlock_Corto_Filter_Command_RunAttributeManipulations::TYPE_IDP @@ -78,9 +74,6 @@ public function getCommands() // Require valid UID and SchacHomeOrganization new EngineBlock_Corto_Filter_Command_ValidateRequiredAttributes(), - // Add guest status (isMemberOf) - new EngineBlock_Corto_Filter_Command_AddGuestStatus(), - // Figure out the collabPersonId new EngineBlock_Corto_Filter_Command_ProvisionUser( $diContainer->getUserDirectory() diff --git a/src/OpenConext/EngineBlock/Metadata/Coins.php b/src/OpenConext/EngineBlock/Metadata/Coins.php index e6eca6709f..d14c69f83d 100644 --- a/src/OpenConext/EngineBlock/Metadata/Coins.php +++ b/src/OpenConext/EngineBlock/Metadata/Coins.php @@ -18,7 +18,6 @@ namespace OpenConext\EngineBlock\Metadata; -use OpenConext\EngineBlock\Metadata\Entity\IdentityProvider; use RobRichards\XMLSecLibs\XMLSecurityKey; /** @@ -68,7 +67,6 @@ public static function createForServiceProvider( } public static function createForIdentityProvider( - $guestQualifier, $schacHomeOrganization, $hidden, $stepupConnections, @@ -81,7 +79,6 @@ public static function createForIdentityProvider( ?string $azureDomainHint = null ) { return new self([ - 'guestQualifier' => $guestQualifier, 'schacHomeOrganization' => $schacHomeOrganization, 'hidden' => $hidden, 'disableScoping' => $disableScoping, @@ -203,11 +200,6 @@ public function defaultRAC() return $this->getValue('defaultRAC'); } - public function guestQualifier() - { - return $this->getValue('guestQualifier', IdentityProvider::GUEST_QUALIFIER_ALL); - } - public function schacHomeOrganization() { return $this->getValue('schacHomeOrganization'); diff --git a/src/OpenConext/EngineBlock/Metadata/Entity/Assembler/PushMetadataAssembler.php b/src/OpenConext/EngineBlock/Metadata/Entity/Assembler/PushMetadataAssembler.php index 6fddacfbb8..f9bff297ad 100644 --- a/src/OpenConext/EngineBlock/Metadata/Entity/Assembler/PushMetadataAssembler.php +++ b/src/OpenConext/EngineBlock/Metadata/Entity/Assembler/PushMetadataAssembler.php @@ -252,7 +252,6 @@ private function assembleIdp(stdClass $connection) $properties = $this->assembleCommon($connection); $properties += $this->assembleSingleSignOnServices($connection); - $properties += $this->setPathFromObjectString(array($connection, 'metadata:coin:guest_qualifier'), 'guestQualifier'); $properties += $this->setPathFromObjectString(array($connection, 'metadata:coin:schachomeorganization'), 'schacHomeOrganization'); $properties += $this->assembleConsentSettings($connection); $properties += $this->setPathFromObjectBool(array($connection, 'metadata:coin:hidden'), 'hidden'); diff --git a/src/OpenConext/EngineBlock/Metadata/Entity/Disassembler/CortoDisassembler.php b/src/OpenConext/EngineBlock/Metadata/Entity/Disassembler/CortoDisassembler.php index 4cc0c5bde0..4603fe97e6 100644 --- a/src/OpenConext/EngineBlock/Metadata/Entity/Disassembler/CortoDisassembler.php +++ b/src/OpenConext/EngineBlock/Metadata/Entity/Disassembler/CortoDisassembler.php @@ -104,8 +104,6 @@ public function translateIdentityProvider(IdentityProvider $entity) ); } - $cortoEntity['GuestQualifier'] = $entity->getCoins()->guestQualifier(); - if ($entity->getCoins()->schacHomeOrganization()) { $cortoEntity['SchacHomeOrganization'] = $entity->getCoins()->schacHomeOrganization(); } diff --git a/src/OpenConext/EngineBlock/Metadata/Entity/IdentityProvider.php b/src/OpenConext/EngineBlock/Metadata/Entity/IdentityProvider.php index 75d1846f4b..166914a613 100644 --- a/src/OpenConext/EngineBlock/Metadata/Entity/IdentityProvider.php +++ b/src/OpenConext/EngineBlock/Metadata/Entity/IdentityProvider.php @@ -50,21 +50,6 @@ #[ORM\Entity] class IdentityProvider extends AbstractRole { - const GUEST_QUALIFIER_ALL = 'All'; - const GUEST_QUALIFIER_SOME = 'Some'; - const GUEST_QUALIFIER_NONE = 'None'; - - /** - * In all-caps to indicate that though the language doesn't allow it, this should be an array constant. - * - * @var string[] - */ - public static $GUEST_QUALIFIERS = array( - self::GUEST_QUALIFIER_ALL, - self::GUEST_QUALIFIER_SOME, - self::GUEST_QUALIFIER_NONE - ); - /** * @var bool */ @@ -145,7 +130,6 @@ public function __construct( string $workflowState = self::WORKFLOW_STATE_DEFAULT, string $manipulation = '', bool $enabledInWayf = true, - string $guestQualifier = self::GUEST_QUALIFIER_ALL, bool $hidden = false, ?string $schacHomeOrganization = null, array $shibMdScopes = array(), @@ -196,7 +180,6 @@ public function __construct( $this->consentSettings = $consentSettings; $this->coins = Coins::createForIdentityProvider( - $guestQualifier, $schacHomeOrganization, $hidden, $stepupConnections, diff --git a/src/OpenConext/EngineBlock/Stepup/StepupEntityFactory.php b/src/OpenConext/EngineBlock/Stepup/StepupEntityFactory.php index 53ea1b7931..cc02867006 100644 --- a/src/OpenConext/EngineBlock/Stepup/StepupEntityFactory.php +++ b/src/OpenConext/EngineBlock/Stepup/StepupEntityFactory.php @@ -72,7 +72,6 @@ public static function idpFrom(StepupEndpoint $stepupEndpoint, ?string $acsLocat IdentityProvider::WORKFLOW_STATE_DEFAULT, '', false, - IdentityProvider::GUEST_QUALIFIER_ALL, true, null, [], @@ -137,7 +136,7 @@ public static function spFrom(StepupEndpoint $stepupEndpoint, ?string $acsLocati [], false, $assertionConsumerServices, - IdentityProvider::GUEST_QUALIFIER_ALL, + true, true, null, [], diff --git a/tests/functional/OpenConext/EngineBlockBundle/Controller/Api/ConnectionsControllerTest.php b/tests/functional/OpenConext/EngineBlockBundle/Controller/Api/ConnectionsControllerTest.php index 73dcb4e8a6..4eb7b4584b 100644 --- a/tests/functional/OpenConext/EngineBlockBundle/Controller/Api/ConnectionsControllerTest.php +++ b/tests/functional/OpenConext/EngineBlockBundle/Controller/Api/ConnectionsControllerTest.php @@ -637,7 +637,6 @@ private function validConnectionsWithCoinsData() 'name' => 'IDP1', 'type' => 'saml20-idp', 'coins' => [ - 'guest_qualifier' => 'guest-qualifier', 'schachomeorganization' => 'schac-home-organization', 'hidden' => '0', // abstract @@ -646,7 +645,6 @@ private function validConnectionsWithCoinsData() 'signature_method' => 'signature-method', ], 'expected-coins' => [ - 'guestQualifier' => 'guest-qualifier', 'schacHomeOrganization' => 'schac-home-organization', 'hidden' => false, // abstract diff --git a/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/PushMetadataAssemblerTest.php b/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/PushMetadataAssemblerTest.php index 6e0d1545cf..6ba075c2e9 100644 --- a/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/PushMetadataAssemblerTest.php +++ b/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/PushMetadataAssemblerTest.php @@ -174,9 +174,6 @@ public function testCoins($coinName, $roleType, $parameter, $type) case 'string-signature-method': $values = $this->validCoinValuesStringSignatureMethod(); break; - case 'string-guest-qualifier': - $values = $this->validCoinValuesStringGuestQualifier(); - break; default: throw new RuntimeException('Unknown coin type'); } @@ -392,7 +389,6 @@ public static function validCoins() ['forceauthn', 'saml20-sp', 'isStepupForceAuthn', 'bool-forceAuthn'], // IDP - ['guest_qualifier', 'saml20-idp', 'guestQualifier', 'string-guest-qualifier'], ['schachomeorganization', 'saml20-idp', 'schacHomeOrganization', 'string'], ['policy_enforcement_decision_required', 'saml20-idp', 'policyEnforcementDecisionRequired', 'bool'], ['hidden', 'saml20-idp', 'hidden', 'bool'], @@ -463,19 +459,6 @@ private function validCoinValuesStringSignatureMethod() ]; } - /** - * The first option is the manage coin value, the second is the expected entity coin value after assembling - * @return array - */ - private function validCoinValuesStringGuestQualifier() - { - return [ - [null, "All"], - ["", ""], - ["string", "string"], - ]; - } - private function validCoinValuesBoolForceAuthn() { return [ diff --git a/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_coin_collab.json b/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_coin_collab.json index 6da6b26d39..7c33dbcdb5 100644 --- a/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_coin_collab.json +++ b/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_coin_collab.json @@ -104,9 +104,7 @@ } ], "certData": "MIIDEzCCAfugAwIBAgIJAKoK/heBjcOYMA0GCSqGSIb3DQEBBQUAMCAxHjAcBgNVBAoMFU9yZ2FuaXphdGlvbiwgQ049T0lEQzAeFw0xNTExMTExMDEyMTVaFw0yNTExMTAxMDEyMTVaMCAxHjAcBgNVBAoMFU9yZ2FuaXphdGlvbiwgQ049T0lEQzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANBGwJ/qpTQNiSgUglSE2UzEkUow+wS8r67etxoEhlzJZfgK/k5TfG1wICDqapHAxEVgUM10aBHRctNocA5wmlHtxdidhzRZroqHwpKy2BmsKX5Z2oK25RLpsyusB1KroemgA/CjUnI6rIL1xxFn3KyOFh1ZBLUQtKNQeMS7HFGgSDAp+sXuTFujz12LFDugX0T0KB5a1+0l8y0PEa0yGa1oi6seONx849ZHxM0PRvUunWkuTM+foZ0jZpFapXe02yWMqhc/2iYMieE/3GvOguJchJt6R+cut8VBb6ubKUIGK7pmoq/TB6DVXpvsHqsDJXechxcicu4pdKVDHSec850CAwEAAaNQME4wHQYDVR0OBBYEFK7RqjoodSYVXGTVEdLf3kJflP/sMB8GA1UdIwQYMBaAFK7RqjoodSYVXGTVEdLf3kJflP/sMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBADNZkxlFXh4F45muCbnQd+WmaXlGvb9tkUyAIxVL8AIu8J18F420vpnGpoUAE+Hy3evBmp2nkrFAgmr055fAjpHeZFgDZBAPCwYd3TNMDeSyMta3Ka+oS7GRFDePkMEm+kH4/rITNKUF1sOvWBTSowk9TudEDyFqgGntcdu/l/zRxvx33y3LMG5USD0x4X4IKjRrRN1BbcKgi8dq10C3jdqNancTuPoqT3WWzRvVtB/q34B7F74/6JzgEoOCEHufBMp4ZFu54P0yEGtWfTwTzuoZobrChVVBt4w/XZagrRtUCDNwRpHNbpjxYudbqLqpi1MQpV9oht/BpTHVJG2i0ro=", - "coin": { - "guest_qualifier": "None" - }, + "coin": {}, "description": { "en": "Dummy IDP" }, diff --git a/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_idp_display_data.json b/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_idp_display_data.json index 3514319897..9948a7e8d0 100644 --- a/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_idp_display_data.json +++ b/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_idp_display_data.json @@ -38,9 +38,7 @@ } ], "certData": "MIIDEzCCAfugAwIBAgIJAKoK/heBjcOYMA0GCSqGSIb3DQEBBQUAMCAxHjAcBgNVBAoMFU9yZ2FuaXphdGlvbiwgQ049T0lEQzAeFw0xNTExMTExMDEyMTVaFw0yNTExMTAxMDEyMTVaMCAxHjAcBgNVBAoMFU9yZ2FuaXphdGlvbiwgQ049T0lEQzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANBGwJ/qpTQNiSgUglSE2UzEkUow+wS8r67etxoEhlzJZfgK/k5TfG1wICDqapHAxEVgUM10aBHRctNocA5wmlHtxdidhzRZroqHwpKy2BmsKX5Z2oK25RLpsyusB1KroemgA/CjUnI6rIL1xxFn3KyOFh1ZBLUQtKNQeMS7HFGgSDAp+sXuTFujz12LFDugX0T0KB5a1+0l8y0PEa0yGa1oi6seONx849ZHxM0PRvUunWkuTM+foZ0jZpFapXe02yWMqhc/2iYMieE/3GvOguJchJt6R+cut8VBb6ubKUIGK7pmoq/TB6DVXpvsHqsDJXechxcicu4pdKVDHSec850CAwEAAaNQME4wHQYDVR0OBBYEFK7RqjoodSYVXGTVEdLf3kJflP/sMB8GA1UdIwQYMBaAFK7RqjoodSYVXGTVEdLf3kJflP/sMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBADNZkxlFXh4F45muCbnQd+WmaXlGvb9tkUyAIxVL8AIu8J18F420vpnGpoUAE+Hy3evBmp2nkrFAgmr055fAjpHeZFgDZBAPCwYd3TNMDeSyMta3Ka+oS7GRFDePkMEm+kH4/rITNKUF1sOvWBTSowk9TudEDyFqgGntcdu/l/zRxvx33y3LMG5USD0x4X4IKjRrRN1BbcKgi8dq10C3jdqNancTuPoqT3WWzRvVtB/q34B7F74/6JzgEoOCEHufBMp4ZFu54P0yEGtWfTwTzuoZobrChVVBt4w/XZagrRtUCDNwRpHNbpjxYudbqLqpi1MQpV9oht/BpTHVJG2i0ro=", - "coin": { - "guest_qualifier": "None" - }, + "coin": {}, "description": { "en": "Dummy IDP" }, diff --git a/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_without_discoveries.json b/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_without_discoveries.json index c2af8b2404..32c5c54641 100644 --- a/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_without_discoveries.json +++ b/tests/integration/OpenConext/EngineBlock/Metadata/Entity/Assembler/fixtures/metadata_without_discoveries.json @@ -24,9 +24,7 @@ } ], "certData": "MIIDEzCCAfugAwIBAgIJAKoK/heBjcOYMA0GCSqGSIb3DQEBBQUAMCAxHjAcBgNVBAoMFU9yZ2FuaXphdGlvbiwgQ049T0lEQzAeFw0xNTExMTExMDEyMTVaFw0yNTExMTAxMDEyMTVaMCAxHjAcBgNVBAoMFU9yZ2FuaXphdGlvbiwgQ049T0lEQzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBANBGwJ/qpTQNiSgUglSE2UzEkUow+wS8r67etxoEhlzJZfgK/k5TfG1wICDqapHAxEVgUM10aBHRctNocA5wmlHtxdidhzRZroqHwpKy2BmsKX5Z2oK25RLpsyusB1KroemgA/CjUnI6rIL1xxFn3KyOFh1ZBLUQtKNQeMS7HFGgSDAp+sXuTFujz12LFDugX0T0KB5a1+0l8y0PEa0yGa1oi6seONx849ZHxM0PRvUunWkuTM+foZ0jZpFapXe02yWMqhc/2iYMieE/3GvOguJchJt6R+cut8VBb6ubKUIGK7pmoq/TB6DVXpvsHqsDJXechxcicu4pdKVDHSec850CAwEAAaNQME4wHQYDVR0OBBYEFK7RqjoodSYVXGTVEdLf3kJflP/sMB8GA1UdIwQYMBaAFK7RqjoodSYVXGTVEdLf3kJflP/sMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBADNZkxlFXh4F45muCbnQd+WmaXlGvb9tkUyAIxVL8AIu8J18F420vpnGpoUAE+Hy3evBmp2nkrFAgmr055fAjpHeZFgDZBAPCwYd3TNMDeSyMta3Ka+oS7GRFDePkMEm+kH4/rITNKUF1sOvWBTSowk9TudEDyFqgGntcdu/l/zRxvx33y3LMG5USD0x4X4IKjRrRN1BbcKgi8dq10C3jdqNancTuPoqT3WWzRvVtB/q34B7F74/6JzgEoOCEHufBMp4ZFu54P0yEGtWfTwTzuoZobrChVVBt4w/XZagrRtUCDNwRpHNbpjxYudbqLqpi1MQpV9oht/BpTHVJG2i0ro=", - "coin": { - "guest_qualifier": "None" - }, + "coin": {}, "description": { "en": "Dummy IDP" }, diff --git a/tests/resources/serviceregistry/idpList.php b/tests/resources/serviceregistry/idpList.php index bbaedd7206..80b6641f01 100644 --- a/tests/resources/serviceregistry/idpList.php +++ b/tests/resources/serviceregistry/idpList.php @@ -4,7 +4,6 @@ $hostUrl .'/authentication/idp/metadata' => array( 'certData' => 'MIIDYzCCAkugAwIBAgIJAMWzFQ+2+7UtMA0GCSqGSIb3DQEBBQUAMEgxFDASBgNVBAMMC0VuZ2luZUJsb2NrMREwDwYDVQQLDAhTZXJ2aWNlczEQMA4GA1UECgwHU1VSRm5ldDELMAkGA1UEBhMCTkwwHhcNMTIwNjEyMDczNjA2WhcNMjIwNjEyMDczNjA2WjBIMRQwEgYDVQQDDAtFbmdpbmVCbG9jazERMA8GA1UECwwIU2VydmljZXMxEDAOBgNVBAoMB1NVUkZuZXQxCzAJBgNVBAYTAk5MMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyl/YsyxuCsqh44RwBz8a0qy15/NbFNL635N0DW2vBVzkppJQN5SJih1aG+ES7pEleWcnvMDyAWSnKTA6uOQCNQIAPJMaJXJuYK8tdTbJWFJTAmiaJxF2NvpA4q4ToY1n1L7cLWBvM9HERLIPC6rFLgv6O05c00s/XqzymlMV9EsAXQbJRp3n5DXNOJrRjfqclK7gpy8O5cD1NWy4OuaA086ipjW6lESKPONTscdFjKDtLarX3JthjAoaK8b/0OCQcbAklaDJXpQTnZNtFZUBWj3n/fuv4jyKvVBWwx5XGACrPEnLTwkLkZZG7oav75jS9sOiDxnTEh+m42Tp17tFZQIDAQABo1AwTjAdBgNVHQ4EFgQU0S9rclotGkC2jUYpy7HTgB/DCU0wHwYDVR0jBBgwFoAU0S9rclotGkC2jUYpy7HTgB/DCU0wDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAQEAHbAa/lSpNf1ayKtq0c513vxboCTaclZ76vmN2jTFpu5qWiwboumRsn9q4Irhxt2kIjdpUHIg8hr46tYtep/tmf9UjbdDeZxZ1sxwhxzrMMjv972/mF1wJcENBZW/degXevz4fiEB//t0wyaA7bWeC2Ry13cvmg0x8fztqJgr4JjjxOSNKbBJ2PmN9ES3hf54UZZTy5iyW2E/3I59uRYyuPhDZDu2Uf0LlEeEuYmbY2AEgPvC+W2eR6axWkw6406jLh0Qf2ph0Wk+1YV94QmHBT9dFCyumnYIByWbqj2TSz2pCu5Gv8Kiik5k/xDDXMQ5W3EHUZIf6gdajhyH3kQkRg==', - 'coin:guest_qualifier' => 'All', 'contacts:0:contactType' => 'technical', 'contacts:0:emailAddress' => 'support@openconext.org', 'contacts:0:givenName' => 'Support', @@ -38,7 +37,6 @@ $hostUrl .'/dummy/idp' => array( 'certData' => 'MIIDrzCCApegAwIBAgIJAOaOFTs6UrvPMA0GCSqGSIb3DQEBBQUAMG4xCzAJBgNVBAYTAk5MMRAwDgYDVQQIDAdVdHJlY2h0MRAwDgYDVQQHDAdVdHJlY2h0MRAwDgYDVQQKDAdTdXJmbmV0MRMwEQYDVQQLDApPcGVuQ29uZXh0MRQwEgYDVQQDDAtFbmdpbmVCbG9jazAeFw0xMzA4MTYwNzQxMDVaFw00MTAxMDEwNzQxMDVaMG4xCzAJBgNVBAYTAk5MMRAwDgYDVQQIDAdVdHJlY2h0MRAwDgYDVQQHDAdVdHJlY2h0MRAwDgYDVQQKDAdTdXJmbmV0MRMwEQYDVQQLDApPcGVuQ29uZXh0MRQwEgYDVQQDDAtFbmdpbmVCbG9jazCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALRDrSUvOMwaLg2UbZaPbxvpRublp5m8kSFRg8hlMnStXPPPSpBbD7hzaV+Ey8bgTcw5mmoxf0wQar2HsH/99W9lvbhVrbhwPJygcSEmPVbjjCZaUx9b/52wjJby6omC0LkXkeJkQYBFYLHPqc32HdlvALSxcW146LWQR8X9cblJuEx9Iz18vHCNnRLI+/w3o5qyI2EG4kJF7vBdhbLMUnaDl6XGvHWyXej35feAhJByeCckxpmqAm79W1a+s6I7dUfLHtFWaHH1+r4dsiOmoViqKGVqtQY18FM2nTfR6VZ+Gj0uvGwCUUrIs7NjGqeWVL1EHQ9uSWhE/BSDKd3ugpcCAwEAAaNQME4wHQYDVR0OBBYEFMdjB4+yV5QG4Ct9RvXSus5dYv+qMB8GA1UdIwQYMBaAFMdjB4+yV5QG4Ct9RvXSus5dYv+qMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAFyq+F3zM+BU85ROM7SZv5poUxKeQ8pP12Sx7LzAsJVZUMtfQwK7WlFkIJXasolL/iuwj/9Y9OMgqUl6IdHrMPNI5znn+Er7wmo2RCbenNAYw9/ywWP/kNa28nb8FVhgX43+0oBf2s8dJngBiLB87Jp/ZGc7CIMqbADJ+ZVGC/6DN9yRXModL4mqnlkXaUVwGoU6EsDbr5WoJyEdpy69HotE7CiIZniMjeVSQ//8enkp7d/rsOAlGCQLD5ajUzaAm3ymIzkMLPGdSpsNjTcMPgEc64ZcOu2gzn8M8/b36nfr3xMS9MutksOPHIO/So7DgFAwvKwiWGk0FUereNM+yMg=', - 'coin:guest_qualifier' => 'All', 'contacts:0:contactType' => 'technical', 'contacts:0:emailAddress' => '', 'contacts:0:givenName' => '', @@ -69,7 +67,6 @@ $hostUrl .'/dummy/idp#2' => array( 'certData' => '', - 'coin:guest_qualifier' => 'All', 'contacts:0:contactType' => 'technical', 'contacts:0:emailAddress' => '', 'contacts:0:givenName' => '', diff --git a/tests/unit/OpenConext/EngineBlock/Metadata/Entity/Disassembler/CortoDisassemblerTest.php b/tests/unit/OpenConext/EngineBlock/Metadata/Entity/Disassembler/CortoDisassemblerTest.php index 56b6986392..d9c6e44b72 100644 --- a/tests/unit/OpenConext/EngineBlock/Metadata/Entity/Disassembler/CortoDisassemblerTest.php +++ b/tests/unit/OpenConext/EngineBlock/Metadata/Entity/Disassembler/CortoDisassemblerTest.php @@ -104,7 +104,6 @@ public function testIdpDisassemble() $this->assertEmpty($cortoIdentityProvider['certificates']); $this->assertEquals($identityProvider->supportedNameIdFormats, $cortoIdentityProvider['NameIDFormats']); $this->assertEquals($identityProvider->workflowState, $cortoIdentityProvider['WorkflowState']); - $this->assertEquals($identityProvider->getCoins()->guestQualifier(), $cortoIdentityProvider['GuestQualifier']); $this->assertEquals($identityProvider->getConsentSettings()->getSpEntityIdsWithoutConsent(), $cortoIdentityProvider['SpsWithoutConsent']); $this->assertEquals($identityProvider->getCoins()->hidden(), $cortoIdentityProvider['isHidden']); $this->assertEmpty($cortoIdentityProvider['shibmd:scopes']);