Thursday, October 30, 2008

SharePoint Initial Impressions

I have recently been doing quite a bit of work with SharePoint. This hasn't been much fun becuase (at least as of yet) it doesn't involve much coding and relies heavily on microsoftian configuration. It has however, been very productive for a fairly low level of effort. In the past week alone, I have rolled out a couple blogs, a shared calendar and a document library, all with fine grain access control, desktop application integration, alerting and workflow. I did have to do a fair degree of customization to these apps, mostly involving disabling or hiding unnecessary functionalities. It has been very interesting learning about the power, limitations and of course bugs of SharePoint.

Friday, September 5, 2008

Single Sign-On with SAML and ColdFusion

My implementation of SAML is largely based on this post by David Rutter which is unfortunately riddled with errors that I spent more time than I would like to admit working through. His post and some of my background knowledge are from Phil Duba's Saml and ColdFusion Series which was very useful until about halfway through part 5 where it ventures out of my comfort zone into compiling java code for use within CF.

What I have done is merge the two approaches into a single solution usable on CF8(and possibly others although it has not been tested) for connecting to PingIdentity's PingFederate Service Provider server such as that used by Rearden Commerce.

PreReqs

  1. Download the binary(bin) Apache XML Security Library. I used the most current version 1.4.2.

  2. Unzip it and copy from xml-security-1_4_2\libs serializer.jar and xmlsec-1.4.2.jar into ColdFusion8\lib and restart the CF service

  3. Buy or Generate an x509 certificate and provide the public portion to you service provider. I will cover this in more depth in another post.


Now we are ready to get into the code.

We start with SAML Assertion XML and fill in the dynamic portions: ID's, dates and username.












#username#

urn:oasis:names:tc:SAML:1.0:cm:bearer









Now we will Sign our XML Assertion:


//injest the xml
samlAssertionElement = samlAssertionXML.getDocumentElement();
samlAssertionDocument = samlAssertionElement.GetOwnerDocument();
samlAssertion = samlAssertionDocument.getFirstChild();

//create the neccesary Java Objects
SignatureSpecNS = CreateObject("Java", "org.apache.xml.security.utils.Constants").SignatureSpecNS;
TransformsClass = CreateObject("Java","org.apache.xml.security.transforms.Transforms");
SecInit = CreateObject("Java", "org.apache.xml.security.Init").Init().init();
XMLSignatureClass = CreateObject("Java", "org.apache.xml.security.signature.XMLSignature");

//set up the signature
sigType = XMLSignatureClass.ALGO_ID_SIGNATURE_RSA_SHA1;
signature = XMLSignatureClass.init(samlAssertionDocument, javacast("string",""), sigType);
samlAssertionElement.insertBefore(signature.getElement(),samlAssertion.getFirstChild());

//set up signature transforms
TransformsClass = CreateObject("Java","org.apache.xml.security.transforms.Transforms");
transformEnvStr = TransformsClass.TRANSFORM_ENVELOPED_SIGNATURE;
transformOmitCommentsStr = TransformsClass.TRANSFORM_C14N_EXCL_OMIT_COMMENTS;
transforms = TransformsClass.init(samlAssertionDocument);
transforms.addTransform(transformEnvStr);
transforms.addTransform(transformOmitCommentsStr);

KeyStoreClass = CreateObject("Java" , "java.security.KeyStore");
//injest your previously created keystore
ksfile = CreateObject("Java", "java.io.File").init("c:\temp.keystore");
inputStream = CreateObject("Java", "java.io.FileInputStream").init(ksfile);
ks = KeyStoreClass.getInstance("JKS");
ks.load(inputStream,"SamlTest");
keypw = "mypass";
key = ks.getKey("SamlTest",keypw.toCharArray());
cert = ks.getCertificate("SamlTest");
publickey = cert.getPublicKey();

signature.addDocument("", transforms);

//optionally include the cert and public key
//signature.addKeyInfo(variables.cert);
//signature.addKeyInfo(variables.publickey);

signature.sign(key);

samlAssertionXML = toBase64(toString(samlAssertionXML), "utf-8");



and then we use a form to post it to the service provider









And there you have homegrown SAML Single Sign-on Solution In ColdFusion.

Here is the source file in it's entirety because blogger has a tendency to mangle code

Please feel free to post questions or comments.

Wednesday, July 30, 2008

FC Recruiting Workflow System

I need to provide a system where users will have the ability to post, comment and approve documents. In addition, his system needs to provide access control and groups. Work flow would also be nice if possible.

Due to the procedural changes being handed down from on high, I need to get this done in under 30 days otherwise, it turns into a pumpkin, or rather a project, as opposed to a Rapid Application and would then require voluminous paperwork and painstaking meetings.

While I could build something custom, I'm not sure that I can get all the desired features done in the time frame, so I'm looking at document management systems and frameworks I could potentially build off of.

I looked at M$ WSS, but quickly scrapped it due to the need to run Visual Studio 2005 on Windows Sever 2003, which makes it much less free (as in beer)

I then looked at Alfresco, which is very pretty but complex. The community edition comes in a large executable, which install a full java stack. It was not as easy to get running as I had hoped.

Next, was Knowledge Tree, which I found to be more usable and intuitive than Alfresco, although slightly less shiny. I am interested in pursuing this one, but also want to continue investigating other lighter weight alternatives such as Genus and others found on SourceForge.

Sunday, July 27, 2008

firefox extensions to have

The best thing about Firefox besides the good standards compliance, speed and reliability are the extension.

I'm running:
  • Adblock Plus
  • All-in-one Sidebar
  • Delicious Bookmards
  • Firebug
  • Web Developer

Wednesday, July 23, 2008

installing MediaWiki on Xampp

I am trying to install MediaWiki on Xampp which i thought would be a cinch but it's actually not.

UPDATE: Heres the solution DoKuWiki

Here is my account of where i am so far so that maybe we can make it easier for the next guy:

I downloaded XAMPP Windows 1.6.7 from http://www.apachefriends.org/en/xampp-windows.html#641
Install and startup goes fine

I downloaded MediaWiki 1.12 from http://www.mediawiki.org/wiki/Download and extract.

I created the wiki db.

I then pull up the wiki page on my localhost. My environment checks out. I proceed to fill out the install form. MediaWiki won't let me use a blank db pw.

I drop the wiki db and then create a new db user and have phpmyadmin create a db with the same name and give the new user full privileges on it.

MediaWiki install completes and tells me to move my config/LocalSettings.php to it's parent directory. I do that and then follow the link MediaWiki gives me and i get:

Warning: domdocument::domdocument() expects at least 1 parameter, 0 given in C:\xampp\htdocs\wiki\includes\Preprocessor_DOM.php on line 566

Fatal error: Call to undefined method domdocument::loadXML() in C:\xampp\htdocs\wiki\includes\Preprocessor_DOM.php on line 568

I Googled "MediaWiki Xampp domdocument" which leads me to a forum posting on apachefriends .org telling me to comment out extension=php_domxml.dll in my php.ini. I do only to recieve yet another error. ugh. more on this saga to come.

Friday, July 18, 2008

What I got out of the uPenn Web Symposium

This week I had the opportunity to attend the uPenn Higher Education Web Symposium.While the this conference was focused on IT Professionals working in Higher Education, there were world renowned experts in the fields of usability, user centered d3sign, CSS, AJAX and many others making it was extremely relevant to my work.

I attended a Full Day Workshop on Web Form Design best Practices by the esteemed Luke Wroblewski who currently works as a Principal Designer and Product Manager for Yahoo!.He also runs a design consultancy, LukeW, and a publication, Functioning Form.

Here are some web form best practices:
  • Put Labels above fields for increased readability and accessibility to screen readers and other languages
  • Don’t include non-required fields when possible.
  • If most fields are required provodie
  • If you are going to provide in-line validation, wait until the user has moved to the next field to validate
  • Make it conversational
  • “Keep, Cut, Postpone, or Explain.”
  • Less is more

These were culled from live to site analytics, usability testing, eye-tracking studies, and best practice surveys.

Thursday, July 3, 2008

Purchase Order System

In addition to my busy schedule of extra curriculars like Philly Ignite and Junto I have been busy at work with internal applications.

One such application is a Purchase Order System which allows for the generation of Purchase Order Documents in PDF. The system automatically notifies purchasing and accounts payable when a new PO is generated and when an existing PO is updated. It also includes search functionality to review existing POs. I used jQuery to do row striping and and highlighting. Here are a couple Screen Shots: