You are here

public function SamlSpConfig::buildForm in SAML Service Provider 8.2

Same name and namespace in other branches
  1. 8.3 src/Form/SamlSpConfig.php \Drupal\saml_sp\Form\SamlSpConfig::buildForm()
  2. 4.x src/Form/SamlSpConfig.php \Drupal\saml_sp\Form\SamlSpConfig::buildForm()
  3. 3.x src/Form/SamlSpConfig.php \Drupal\saml_sp\Form\SamlSpConfig::buildForm()

Form constructor.

Parameters

array $form: An associative array containing the structure of the form.

\Drupal\Core\Form\FormStateInterface $form_state: The current state of the form.

Return value

array The form structure.

Overrides ConfigFormBase::buildForm

File

src/Form/SamlSpConfig.php, line 120
Contains \Drupal\saml_sp\Form\SamlSpConfigSPForm.

Class

SamlSpConfig

Namespace

Drupal\saml_sp\Form

Code

public function buildForm(array $form = [], FormStateInterface $form_state) {
  $config = $this->configFactory
    ->get('saml_sp.settings');
  $form['entity_id'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('Entity ID'),
    '#description' => $this
      ->t('This is the unique name that the Identity Providers will know your site as. Defaults to the login page %login_url', array(
      '%login_url' => \Drupal::url('user.page', array(), array(
        'absolute' => TRUE,
      )),
    )),
    '#default_value' => $config
      ->get('entity_id'),
    '#disabled' => $this
      ->isOverridden('entity_id'),
  );
  $form['contact'] = array(
    '#type' => 'fieldset',
    '#title' => $this
      ->t('Contact Information'),
    '#description' => $this
      ->t('Information to be included in the federation metadata.'),
    '#tree' => TRUE,
  );
  $form['contact']['technical'] = array(
    '#type' => 'fieldset',
    '#title' => $this
      ->t('Technical'),
  );
  $form['contact']['technical']['name'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('Name'),
    '#default_value' => $config
      ->get('contact.technical.name'),
    '#disabled' => $this
      ->isOverridden('contact.technical.name'),
  );
  $form['contact']['technical']['email'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('Email'),
    '#default_value' => $config
      ->get('contact.technical.email'),
    '#disabled' => $this
      ->isOverridden('contact.technical.email'),
  );
  $form['contact']['support'] = array(
    '#type' => 'fieldset',
    '#title' => $this
      ->t('Support'),
  );
  $form['contact']['support']['name'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('Name'),
    '#default_value' => $config
      ->get('contact.support.name'),
    '#disabled' => $this
      ->isOverridden('contact.support.name'),
  );
  $form['contact']['support']['email'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('Email'),
    '#default_value' => $config
      ->get('contact.support.email'),
    '#disabled' => $this
      ->isOverridden('contact.support.email'),
  );
  $form['organization'] = array(
    '#type' => 'fieldset',
    '#title' => $this
      ->t('Organization'),
    '#description' => $this
      ->t('Organization information for the federation metadata'),
    '#tree' => TRUE,
  );
  $form['organization']['name'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('Name'),
    '#description' => $this
      ->t('This is a short name for the organization'),
    '#default_value' => $config
      ->get('organization.name'),
    '#disabled' => $this
      ->isOverridden('organization.name'),
  );
  $form['organization']['display_name'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('Display Name'),
    '#description' => $this
      ->t('This is a long name for the organization'),
    '#default_value' => $config
      ->get('organization.display_name'),
    '#disabled' => $this
      ->isOverridden('organization.display_name'),
  );
  $form['organization']['url'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('URL'),
    '#description' => $this
      ->t('This is a URL for the organization'),
    '#default_value' => $config
      ->get('organization.url'),
    '#disabled' => $this
      ->isOverridden('organization.url'),
  );
  $form['strict'] = array(
    '#type' => 'checkbox',
    '#title' => t('Strict Protocol'),
    '#description' => t('SAML 2 Strict protocol will be used.'),
    '#default_value' => $config
      ->get('strict'),
    '#disabled' => $this
      ->isOverridden('strict'),
  );
  $form['security'] = array(
    '#type' => 'fieldset',
    '#title' => $this
      ->t('Security'),
    '#tree' => TRUE,
  );
  $form['security']['offered'] = array(
    '#markup' => t('Signatures and Encryptions Offered:'),
  );
  $form['security']['nameIdEncrypted'] = array(
    '#type' => 'checkbox',
    '#title' => $this
      ->t('NameID Encrypted'),
    '#default_value' => $config
      ->get('security.nameIdEncrypted'),
    '#disabled' => $this
      ->isOverridden('security.nameIdEncrypted'),
  );
  $form['security']['authnRequestsSigned'] = array(
    '#type' => 'checkbox',
    '#title' => $this
      ->t('Authn Requests Signed'),
    '#default_value' => $config
      ->get('security.authnRequestsSigned'),
    '#disabled' => $this
      ->isOverridden('security.authnRequestsSigned'),
  );
  $form['security']['logoutRequestSigned'] = array(
    '#type' => 'checkbox',
    '#title' => $this
      ->t('Logout Requests Signed'),
    '#default_value' => $config
      ->get('security.logoutRequestSigned'),
    '#disabled' => $this
      ->isOverridden('security.logoutRequestSigned'),
  );
  $form['security']['logoutResponseSigned'] = array(
    '#type' => 'checkbox',
    '#title' => $this
      ->t('Logout Response Signed'),
    '#default_value' => $config
      ->get('security.logoutResponseSigned'),
    '#disabled' => $this
      ->isOverridden('security.logoutResponseSigned'),
  );
  $form['security']['required'] = array(
    '#markup' => $this
      ->t('Signatures and Encryptions Required:'),
  );
  $form['security']['wantMessagesSigned'] = array(
    '#type' => 'checkbox',
    '#title' => $this
      ->t('Want Messages Signed'),
    '#default_value' => $config
      ->get('security.wantMessagesSigned'),
    '#disabled' => $this
      ->isOverridden('security.wantMessagesSigned'),
  );
  $form['security']['wantAssertionsSigned'] = array(
    '#type' => 'checkbox',
    '#title' => $this
      ->t('Want Assertions Signed'),
    '#default_value' => $config
      ->get('security.wantAssertionsSigned'),
    '#disabled' => $this
      ->isOverridden('security.wantAssertionsSigned'),
  );
  $form['security']['wantNameIdEncrypted'] = array(
    '#type' => 'checkbox',
    '#title' => $this
      ->t('Want NameID Encrypted'),
    '#default_value' => $config
      ->get('security.wantNameIdEncrypted'),
    '#disabled' => $this
      ->isOverridden('security.wantNameIdEncrypted'),
  );
  $form['security']['metadata'] = array(
    '#markup' => $this
      ->t('Metadata:'),
  );
  $form['security']['signMetaData'] = array(
    '#type' => 'checkbox',
    '#title' => $this
      ->t('Sign Meta Data'),
    '#default_value' => $config
      ->get('security.signMetaData'),
    '#disabled' => $this
      ->isOverridden('security.signMetaData'),
  );
  $form['security']['signatureAlgorithm'] = [
    '#type' => 'select',
    '#title' => $this
      ->t('Signature Algorithm'),
    '#description' => $this
      ->t('What algorithm do you want used for messages signatures?'),
    '#options' => [
      //XMLSecurityKey::DSA_SHA1 => 'DSA SHA-1',
      XMLSecurityKey::RSA_SHA1 => 'SHA-1',
      XMLSecurityKey::RSA_SHA256 => 'SHA-256',
      XMLSecurityKey::RSA_SHA384 => 'SHA-384',
      XMLSecurityKey::RSA_SHA512 => 'SHA-512',
    ],
    '#default_value' => $config
      ->get('security.signatureAlgorithm'),
    '#disabled' => $this
      ->isOverridden('security.signatureAlgorithm'),
  ];
  $form['security']['lowercaseUrlencoding'] = [
    '#type' => 'checkbox',
    '#title' => $this
      ->t('Lowercase Url Encoding'),
    //'#description'    => $this->t(""),
    '#default_value' => $config
      ->get('security.lowercaseUrlencoding'),
    '#disabled' => $this
      ->isOverridden('security.lowercaseUrlencoding'),
  ];
  $form['cert_location'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('Certificate Location'),
    '#description' => $this
      ->t('The location of the x.509 certificate file on the server. This must be a location that PHP can read.'),
    '#default_value' => $config
      ->get('cert_location'),
    '#disabled' => $this
      ->isOverridden('cert_location'),
    '#states' => array(
      'required' => array(
        [
          'input[name="security[authnRequestsSigned]"' => [
            'checked' => TRUE,
          ],
        ],
        [
          'input[name="security[logoutRequestSigned]"' => [
            'checked' => TRUE,
          ],
        ],
        [
          'input[name="security[logoutResponseSigned]"' => [
            'checked' => TRUE,
          ],
        ],
        [
          'input[name="security[wantNameIdEncrypted]"' => [
            'checked' => TRUE,
          ],
        ],
        [
          'input[name="security[signMetaData]"' => [
            'checked' => TRUE,
          ],
        ],
      ),
    ),
    '#suffix' => $this
      ->certInfo($config
      ->get('cert_location')),
  );
  $form['key_location'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('Key Location'),
    '#description' => $this
      ->t('The location of the x.509 key file on the server. This must be a location that PHP can read.'),
    '#default_value' => $config
      ->get('key_location'),
    '#disabled' => $this
      ->isOverridden('key_location'),
    '#states' => array(
      'required' => array(
        [
          'input[name="security[authnRequestsSigned]"' => [
            'checked' => TRUE,
          ],
        ],
        [
          'input[name="security[logoutRequestSigned]"' => [
            'checked' => TRUE,
          ],
        ],
        [
          'input[name="security[logoutResponseSigned]"' => [
            'checked' => TRUE,
          ],
        ],
        [
          'input[name="security[wantNameIdEncrypted]"' => [
            'checked' => TRUE,
          ],
        ],
        [
          'input[name="security[signMetaData]"' => [
            'checked' => TRUE,
          ],
        ],
      ),
    ),
  );
  $form['new_cert_location'] = array(
    '#type' => 'textfield',
    '#title' => $this
      ->t('New Certificate Location'),
    '#description' => $this
      ->t('The location of the x.509 certificate file on the server. If the certificate above is about to expire add your new certificate here after you have obtained it. This will add the new certificate to the metadata to let the IdP know of the new certificate. This must be a location that PHP can read.'),
    '#default_value' => $config
      ->get('new_cert_location'),
    '#disabled' => $this
      ->isOverridden('new_cert_location'),
    '#suffix' => $this
      ->certInfo($config
      ->get('new_cert_location')),
  );
  $error = FALSE;
  try {
    $metadata = saml_sp__get_metadata(FALSE);
    if (is_array($metadata)) {
      if (isset($metadata[1])) {
        $errors = $metadata[1];
      }
      $metadata = $metadata[0];
    }
  } catch (Exception $e) {
    drupal_set_message($this
      ->t('Attempt to create metadata failed: %message.', array(
      '%message' => $e
        ->getMessage(),
    )), 'error');
    $metadata = '';
    $error = $e;
  }
  if (empty($metadata) && $error) {
    $no_metadata = $this
      ->t('There is currently no metadata because of the following error: %error. Please resolve the error and return here for your metadata.', array(
      '%error' => $error
        ->getMessage(),
    ));
  }
  $form['metadata'] = array(
    '#type' => 'fieldset',
    '#collapsed' => TRUE,
    '#collapsible' => TRUE,
    '#title' => $this
      ->t('Metadata'),
    '#description' => $this
      ->t('This is the Federation Metadata for this SP, please provide this to the IdP to create a Relying Party Trust (RPT)'),
  );
  if ($metadata) {
    $form['metadata']['data'] = array(
      '#type' => 'textarea',
      '#title' => $this
        ->t('XML Metadata'),
      '#description' => $this
        ->t('This metadata can also be accessed <a href="@url" target="_blank">here</a>', array(
        '@url' => Url::fromRoute('saml_sp.metadata')
          ->toString(),
      )),
      '#disabled' => TRUE,
      '#rows' => 20,
      '#default_value' => trim($metadata),
    );
  }
  else {
    $form['metadata']['none'] = array(
      '#markup' => $no_metadata,
    );
  }
  $form['debug'] = array(
    '#type' => 'checkbox',
    '#title' => $this
      ->t('Turn on debugging'),
    '#description' => $this
      ->t('Some debugging messages will be shown.'),
    '#default_value' => $config
      ->get('debug'),
    '#disabled' => $this
      ->isOverridden('debug'),
  );
  return parent::buildForm($form, $form_state);
}