mirror of https://github.com/apache/cloudstack.git
SAML2UserAuthenticator: check that request params has SAMLResponse
Signed-off-by: Rohit Yadav <rohit.yadav@shapeblue.com>
This commit is contained in:
parent
7ee4176c7a
commit
ad13d3d747
|
|
@ -48,8 +48,8 @@ public class SAML2UserAuthenticator extends DefaultUserAuthenticator {
|
||||||
return new Pair<Boolean, ActionOnFailedAuthentication>(false, null);
|
return new Pair<Boolean, ActionOnFailedAuthentication>(false, null);
|
||||||
} else {
|
} else {
|
||||||
User user = _userDao.getUser(userAccount.getId());
|
User user = _userDao.getUser(userAccount.getId());
|
||||||
// TODO: check SAMLRequest, signature etc. from requestParameters
|
if (user != null && SAMLUtils.checkSAMLUserId(user.getUuid()) &&
|
||||||
if (user != null && SAMLUtils.checkSAMLUserId(user.getUuid())) {
|
requestParameters.containsKey(SAMLUtils.SAML_RESPONSE)) {
|
||||||
return new Pair<Boolean, ActionOnFailedAuthentication>(true, null);
|
return new Pair<Boolean, ActionOnFailedAuthentication>(true, null);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue