Eyebrow Text
BLOG
Title
OGNL: What about those curly braces?
Subtitle
Discover how OGNL curly braces enable multi-valued attribute creation in PingFederate SAML assertions.

If you have seen more complex OGNL expressions you probably have seen the use of curly braces { } with expressions in them that seem to do wonderful things, but definitely looks nothing like Java. This is one of the more interesting and powerful features of OGNL and will take 2 or 3 posts to cover.

The challenge may be where to start.

Let's first introduce a PingFederate class that is part of the SDK and is very handy in working with OGNL:

html
<pre><code>org.sourceid.saml20.adapter.attribute.AttributeValue</code></pre>
css
js
document.querySelectorAll('.open-html pre code').forEach(function (c) { c.textContent = c.textContent.replace(/\n[ \t]+/g, '\n'); });

See the complete list of articles in my OGNL series at the end of this entry.

This class represents the attribute object in PingFederate and when you use the following in your expression:

html
<pre><code>#this.get("SAML_SUBJECT")</code></pre>
css
js

It actually returns an instance of this type of object and if it is a single value attribute you can use the toString method as we did in the second article of this series to get the actual value. This class is very flexible and you can use it to create multi-valued attributes along with single-value attributes.

You can use the curly braces to create an array (we first talked about arrays last week) of objects, for example, by doing something like this:

html
<pre><code>{"first", "second", "third"}</code></pre>
css
js

This expression creates a java.util.Collection object. Combining the PingFederate class and the above code you can create an attribute that will be sent as a multi-valued attribute in the SAML assertion. The expression would look like:

html
<pre><code>new org.sourceid.saml20.adapter.attribute.AttributeValue({"first", "second", "third"})</code></pre>
css
js

The following screenshot shows the expression in PingFederate:

image
/content/dam/picr/dia/bl/support/05a_ognl_00.png
alt-text
caption
width
1715px
height
alignment
left
id
link-url
disable-lazy-load

The resulting assertion would would look like the following in the server log:

html
<pre><code><saml:Attribute Name="attribute04" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">

<saml:AttributeValue xsi:type="xs:string" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">first</saml:AttributeValue>

<saml:AttributeValue xsi:type="xs:string" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">second</saml:AttributeValue>

<saml:AttributeValue xsi:type="xs:string" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">third</saml:AttributeValue>

</saml:Attribute></code></pre>
css
js
var b = document.currentScript && document.currentScript.parentElement; (b || document).querySelectorAll('pre code').forEach(function (c) { if (c.textContent.replace(/\s/g, '') === 'firstsecondthird') { c.textContent = '<saml:Attribute Name="attribute04" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">\n <saml:AttributeValue xsi:type="xs:string" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">first</saml:AttributeValue>\n <saml:AttributeValue xsi:type="xs:string" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">second</saml:AttributeValue>\n <saml:AttributeValue xsi:type="xs:string" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">third</saml:AttributeValue>\n</saml:Attribute>'; } });

The following screenshot shows the result in the application:

image
/content/dam/picr/dia/bl/support/05a_ognl_01.png
alt-text
caption
width
579px
height
alignment
left
id
link-url
disable-lazy-load

Stay tuned for more about OGNL. In the meantime please leave a comment on this post and let me know what topics you would like to see. Follow me on Twitter: @jdasilvaPI

******************************************

OGNL Blog Series:

  1. Introduction to OGNL
  2. A simple OGNL expression
  3. Declaring variables in OGNL
  4. Method calls in OGNL
  5. Arrays in OGNL
  6. OGNL: What about those curly braces?
  7. Looping in OGNL
  8. Looping in OGNL take 2
  9. So what exactly is #this in OGNL?
  10. A continuing look at #this variable in OGNL
  11. Functions in OGNL
  12. Misc Topics in OGNL

John DaSilva develops training and solutions at Ping Identity.