Added SAML-based Web Single-Sign-On as new authentication method available in pre...
authorDavid A. Velasco <dvelasco@solidgear.es>
Thu, 25 Jul 2013 15:29:52 +0000 (17:29 +0200)
committerDavid A. Velasco <dvelasco@solidgear.es>
Thu, 25 Jul 2013 15:29:52 +0000 (17:29 +0200)
res/layout-land/account_setup.xml
res/layout/account_setup.xml
res/values/branding.xml [deleted file]
res/values/oauth2_configuration.xml
res/values/setup.xml [new file with mode: 0644]
res/values/strings.xml
src/com/owncloud/android/authentication/AccountAuthenticator.java
src/com/owncloud/android/authentication/AuthenticatorActivity.java

index 150893a..5b3ec5d 100644 (file)
                                        android:onClick="onCheckClick"\r
                                        android:text="@string/oauth_check_onoff"\r
                                        android:textAppearance="?android:attr/textAppearanceSmall"\r
                                        android:onClick="onCheckClick"\r
                                        android:text="@string/oauth_check_onoff"\r
                                        android:textAppearance="?android:attr/textAppearanceSmall"\r
-                                       android:visibility="gone"\r
                                        />\r
                \r
                                <EditText\r
                                        />\r
                \r
                                <EditText\r
                                        android:singleLine="true"\r
                                        android:inputType="textUri"\r
                                        android:visibility="gone" >\r
                                        android:singleLine="true"\r
                                        android:inputType="textUri"\r
                                        android:visibility="gone" >\r
-                                       <requestFocus />\r
                                </EditText>            \r
                                \r
                                <EditText\r
                                </EditText>            \r
                                \r
                                <EditText\r
                                        <requestFocus />\r
                                </EditText>            \r
                \r
                                        <requestFocus />\r
                                </EditText>            \r
                \r
+                       <EditText\r
+                           android:id="@+id/account_name"\r
+                           android:layout_width="match_parent"\r
+                           android:layout_height="wrap_content"\r
+                           android:ems="10"\r
+                           android:hint="@string/auth_account_name"\r
+                           android:inputType="textNoSuggestions" \r
+                           android:visibility="gone" />\r
+                       \r
+                       <WebView\r
+                           android:id="@+id/web_sso_view" \r
+                           android:layout_width="match_parent"\r
+                           android:layout_height="wrap_content"\r
+                           android:visibility="gone" />\r
+               \r
                                <EditText\r
                                        android:id="@+id/account_username"\r
                                        android:layout_width="match_parent"\r
                                <EditText\r
                                        android:id="@+id/account_username"\r
                                        android:layout_width="match_parent"\r
index 04da4be..7cac19e 100644 (file)
             android:onClick="onCheckClick"\r
             android:text="@string/oauth_check_onoff"\r
             android:textAppearance="?android:attr/textAppearanceSmall"\r
             android:onClick="onCheckClick"\r
             android:text="@string/oauth_check_onoff"\r
             android:textAppearance="?android:attr/textAppearanceSmall"\r
-            android:visibility="gone" />\r
+            />\r
 \r
         <EditText\r
             android:id="@+id/oAuthEntryPoint_1"\r
             android:layout_width="match_parent"\r
             android:layout_height="wrap_content"\r
             android:ems="10"\r
 \r
         <EditText\r
             android:id="@+id/oAuthEntryPoint_1"\r
             android:layout_width="match_parent"\r
             android:layout_height="wrap_content"\r
             android:ems="10"\r
-            android:inputType="textUri"\r
-            android:singleLine="true"\r
+                       android:enabled="false"\r
             android:text="@string/oauth2_url_endpoint_auth"\r
             android:text="@string/oauth2_url_endpoint_auth"\r
+            android:singleLine="true"\r
+            android:inputType="textUri"\r
             android:visibility="gone" >\r
         </EditText>\r
 \r
             android:visibility="gone" >\r
         </EditText>\r
 \r
             android:layout_width="match_parent"\r
             android:layout_height="wrap_content"\r
             android:ems="10"\r
             android:layout_width="match_parent"\r
             android:layout_height="wrap_content"\r
             android:ems="10"\r
-            android:inputType="textUri"\r
-            android:singleLine="true"\r
+                       android:enabled="false"\r
             android:text="@string/oauth2_url_endpoint_access"\r
             android:text="@string/oauth2_url_endpoint_access"\r
+            android:singleLine="true"\r
+            android:inputType="textUri"\r
+            android:visibility="gone" />\r
+\r
+        <EditText\r
+            android:id="@+id/account_name"\r
+            android:layout_width="match_parent"\r
+            android:layout_height="wrap_content"\r
+            android:ems="10"\r
+            android:hint="@string/auth_account_name"\r
+            android:inputType="textNoSuggestions" \r
+            android:visibility="gone" />\r
+        \r
+        <WebView\r
+            android:id="@+id/web_sso_view" \r
+            android:layout_width="match_parent"\r
+            android:layout_height="wrap_content"\r
             android:visibility="gone" />\r
 \r
         <EditText\r
             android:visibility="gone" />\r
 \r
         <EditText\r
             android:layout_height="wrap_content"\r
             android:ems="10"\r
             android:hint="@string/auth_username"\r
             android:layout_height="wrap_content"\r
             android:ems="10"\r
             android:hint="@string/auth_username"\r
-            android:inputType="textNoSuggestions" />\r
+            android:inputType="textNoSuggestions" \r
+                       />\r
 \r
                <EditText\r
                    android:id="@+id/account_password"\r
 \r
                <EditText\r
                    android:id="@+id/account_password"\r
                    android:drawablePadding="5dp"\r
                    android:ems="10"\r
                    android:hint="@string/auth_password"\r
                    android:drawablePadding="5dp"\r
                    android:ems="10"\r
                    android:hint="@string/auth_password"\r
-                   android:inputType="textPassword" />\r
+                   android:inputType="textPassword" \r
+            />\r
         \r
         <TextView\r
             android:id="@+id/auth_status_text"\r
         \r
         <TextView\r
             android:id="@+id/auth_status_text"\r
diff --git a/res/values/branding.xml b/res/values/branding.xml
deleted file mode 100644 (file)
index f312dad..0000000
+++ /dev/null
@@ -1,5 +0,0 @@
-<?xml version="1.0" encoding="utf-8"?>
-<resources>
-    <string name="server_url"></string>
-    <bool name="show_server_url_input">true</bool>
-</resources>
index 5fbef7c..f8e0f51 100644 (file)
@@ -1,10 +1,5 @@
 <?xml version="1.0" encoding="utf-8"?>
 <resources>
 <?xml version="1.0" encoding="utf-8"?>
 <resources>
-    <!-- Flag to configure OAuth availability in the app.
-        3 valid values now: on, off, optional  
-     -->
-    <string name="oauth2_mode">off</string>
-    
     <!-- constants that must be respected by the authorization server; if changed, the app must be rebuild -->
     <string name="oauth2_redirect_scheme">owncloud</string>
     <string name="oauth2_redirect_uri">owncloud://callback</string>
     <!-- constants that must be respected by the authorization server; if changed, the app must be rebuild -->
     <string name="oauth2_redirect_scheme">owncloud</string>
     <string name="oauth2_redirect_uri">owncloud://callback</string>
diff --git a/res/values/setup.xml b/res/values/setup.xml
new file mode 100644 (file)
index 0000000..b3cb69b
--- /dev/null
@@ -0,0 +1,10 @@
+<?xml version="1.0" encoding="utf-8"?>
+<resources>
+    <string name="server_url"></string>
+    <bool name="show_server_url_input">true</bool>
+    
+    <!-- Flags to setup the authentication methods available in the app -->
+    <string name="auth_method_oauth2">off</string>
+    <string name="auth_method_saml_web_sso">off</string>
+    
+</resources>
index 8c273bd..30ec04f 100644 (file)
@@ -49,6 +49,7 @@
     <string name="prefs_log_delete_history_button">Delete History</string>
     
     <string name="auth_check_server">Check Server</string>
     <string name="prefs_log_delete_history_button">Delete History</string>
     
     <string name="auth_check_server">Check Server</string>
+    <string name="auth_account_name">Account name</string>
     <string name="auth_host_url">Server address</string>
     <string name="auth_username">Username</string>
     <string name="auth_password">Password</string>
     <string name="auth_host_url">Server address</string>
     <string name="auth_username">Username</string>
     <string name="auth_password">Password</string>
index 30eda59..2b58d43 100644 (file)
@@ -46,6 +46,7 @@ public class AccountAuthenticator extends AbstractAccountAuthenticator {
     public static final String AUTH_TOKEN_TYPE_PASSWORD = "owncloud.password";
     public static final String AUTH_TOKEN_TYPE_ACCESS_TOKEN = "owncloud.oauth2.access_token";
     public static final String AUTH_TOKEN_TYPE_REFRESH_TOKEN = "owncloud.oauth2.refresh_token";
     public static final String AUTH_TOKEN_TYPE_PASSWORD = "owncloud.password";
     public static final String AUTH_TOKEN_TYPE_ACCESS_TOKEN = "owncloud.oauth2.access_token";
     public static final String AUTH_TOKEN_TYPE_REFRESH_TOKEN = "owncloud.oauth2.refresh_token";
+    public static final String AUTH_TOKEN_TYPE_SAML_WEB_SSO_SESSION_COOKIE = "owncloud.saml.web_sso.session_cookie";
 
     public static final String KEY_AUTH_TOKEN_TYPE = "authTokenType";
     public static final String KEY_REQUIRED_FEATURES = "requiredFeatures";
 
     public static final String KEY_AUTH_TOKEN_TYPE = "authTokenType";
     public static final String KEY_REQUIRED_FEATURES = "requiredFeatures";
@@ -75,6 +76,10 @@ public class AccountAuthenticator extends AbstractAccountAuthenticator {
      * Flag signaling if the ownCloud server can be accessed with OAuth2 access tokens.
      */
     public static final String KEY_SUPPORTS_OAUTH2 = "oc_supports_oauth2";
      * Flag signaling if the ownCloud server can be accessed with OAuth2 access tokens.
      */
     public static final String KEY_SUPPORTS_OAUTH2 = "oc_supports_oauth2";
+    /**
+     * Flag signaling if the ownCloud server can be accessed with session cookies from SAML-based web single-sign-on.
+     */
+    public static final String KEY_SUPPORTS_SAML_WEB_SSO = "oc_supports_saml_web_sso";
     
     private static final String TAG = AccountAuthenticator.class.getSimpleName();
     
     
     private static final String TAG = AccountAuthenticator.class.getSimpleName();
     
index 76041c1..d1f79cf 100644 (file)
@@ -57,6 +57,7 @@ import android.view.View.OnFocusChangeListener;
 import android.view.View.OnTouchListener;\r
 import android.view.Window;\r
 import android.view.inputmethod.EditorInfo;\r
 import android.view.View.OnTouchListener;\r
 import android.view.Window;\r
 import android.view.inputmethod.EditorInfo;\r
+import android.webkit.WebView;\r
 import android.widget.CheckBox;\r
 import android.widget.EditText;\r
 import android.widget.Button;\r
 import android.widget.CheckBox;\r
 import android.widget.EditText;\r
 import android.widget.Button;\r
@@ -95,13 +96,18 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
     private static final String KEY_SERVER_STATUS_ICON = "SERVER_STATUS_ICON";\r
     private static final String KEY_IS_SSL_CONN = "IS_SSL_CONN";\r
     private static final String KEY_PASSWORD_VISIBLE = "PASSWORD_VISIBLE";\r
     private static final String KEY_SERVER_STATUS_ICON = "SERVER_STATUS_ICON";\r
     private static final String KEY_IS_SSL_CONN = "IS_SSL_CONN";\r
     private static final String KEY_PASSWORD_VISIBLE = "PASSWORD_VISIBLE";\r
+    private static final String KEY_AUTH_METHOD = "AUTH_METHOD";\r
     private static final String KEY_AUTH_STATUS_TEXT = "AUTH_STATUS_TEXT";\r
     private static final String KEY_AUTH_STATUS_ICON = "AUTH_STATUS_ICON";\r
     private static final String KEY_REFRESH_BUTTON_ENABLED = "KEY_REFRESH_BUTTON_ENABLED";\r
 \r
     private static final String KEY_AUTH_STATUS_TEXT = "AUTH_STATUS_TEXT";\r
     private static final String KEY_AUTH_STATUS_ICON = "AUTH_STATUS_ICON";\r
     private static final String KEY_REFRESH_BUTTON_ENABLED = "KEY_REFRESH_BUTTON_ENABLED";\r
 \r
-    private static final String OAUTH_MODE_ON = "on";\r
-    private static final String OAUTH_MODE_OFF = "off";\r
-    private static final String OAUTH_MODE_OPTIONAL = "optional";\r
+    private static final String AUTH_ON = "on";\r
+    private static final String AUTH_OFF = "off";\r
+    private static final String AUTH_OPTIONAL = "optional";\r
+    \r
+    private static final int AUTH_METHOD_BASIC_HTTP = 0;\r
+    private static final int AUTH_METHOD_OAUTH2 = 1;\r
+    private static final int AUTH_METHOD_SAML_WEB_SSO = 2;\r
 \r
     private static final int DIALOG_LOGIN_PROGRESS = 0;\r
     private static final int DIALOG_SSL_VALIDATOR = 1;\r
 \r
     private static final int DIALOG_LOGIN_PROGRESS = 0;\r
     private static final int DIALOG_SSL_VALIDATOR = 1;\r
@@ -117,6 +123,7 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
     private int mServerStatusText, mServerStatusIcon;\r
     private boolean mServerIsChecked, mServerIsValid, mIsSslConn;\r
     private int mAuthStatusText, mAuthStatusIcon;    \r
     private int mServerStatusText, mServerStatusIcon;\r
     private boolean mServerIsChecked, mServerIsValid, mIsSslConn;\r
     private int mAuthStatusText, mAuthStatusIcon;    \r
+    private TextView mAuthStatusLayout;\r
 \r
     private final Handler mHandler = new Handler();\r
     private Thread mOperationThread;\r
 \r
     private final Handler mHandler = new Handler();\r
     private Thread mOperationThread;\r
@@ -132,20 +139,24 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
     private Account mAccount;\r
 \r
     private EditText mHostUrlInput;\r
     private Account mAccount;\r
 \r
     private EditText mHostUrlInput;\r
+    private boolean mHostUrlInputEnabled;\r
     private View mRefreshButton;\r
     private View mRefreshButton;\r
+\r
+    private int mCurrentAuthorizationMethod;  \r
+    \r
     private EditText mUsernameInput;\r
     private EditText mPasswordInput;\r
     private EditText mUsernameInput;\r
     private EditText mPasswordInput;\r
+    \r
     private CheckBox mOAuth2Check;\r
     private String mOAuthAccessToken;\r
     private CheckBox mOAuth2Check;\r
     private String mOAuthAccessToken;\r
-    private View mOkButton;\r
-    private TextView mAuthStatusLayout;\r
-\r
+    \r
     private TextView mOAuthAuthEndpointText;\r
     private TextView mOAuthTokenEndpointText;\r
     \r
     private TextView mOAuthAuthEndpointText;\r
     private TextView mOAuthTokenEndpointText;\r
     \r
-    private boolean mRefreshButtonEnabled;\r
+    private TextView mAccountNameInput;\r
+    private WebView mWebSsoView;\r
     \r
     \r
-    private boolean mHostUrlInputEnabled;\r
+    private View mOkButton;\r
 \r
 \r
     /**\r
 \r
 \r
     /**\r
@@ -167,6 +178,8 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
         mOAuthAuthEndpointText = (TextView)findViewById(R.id.oAuthEntryPoint_1);\r
         mOAuthTokenEndpointText = (TextView)findViewById(R.id.oAuthEntryPoint_2);\r
         mOAuth2Check = (CheckBox) findViewById(R.id.oauth_onOff_check);\r
         mOAuthAuthEndpointText = (TextView)findViewById(R.id.oAuthEntryPoint_1);\r
         mOAuthTokenEndpointText = (TextView)findViewById(R.id.oAuthEntryPoint_2);\r
         mOAuth2Check = (CheckBox) findViewById(R.id.oauth_onOff_check);\r
+        mAccountNameInput = (EditText) findViewById(R.id.account_name);\r
+        mWebSsoView = (WebView) findViewById(R.id.web_sso_view);\r
         mOkButton = findViewById(R.id.buttonOK);\r
         mAuthStatusLayout = (TextView) findViewById(R.id.auth_status_text); \r
         \r
         mOkButton = findViewById(R.id.buttonOK);\r
         mAuthStatusLayout = (TextView) findViewById(R.id.auth_status_text); \r
         \r
@@ -207,9 +220,6 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
             mAuthStatusText = mAuthStatusIcon = 0;\r
 \r
             /// retrieve extras from intent\r
             mAuthStatusText = mAuthStatusIcon = 0;\r
 \r
             /// retrieve extras from intent\r
-            String tokenType = getIntent().getExtras().getString(AccountAuthenticator.KEY_AUTH_TOKEN_TYPE);\r
-            boolean oAuthRequired = AccountAuthenticator.AUTH_TOKEN_TYPE_ACCESS_TOKEN.equals(tokenType) || OAUTH_MODE_ON.equals(getString(R.string.oauth2_mode));\r
-\r
             mAccount = getIntent().getExtras().getParcelable(EXTRA_ACCOUNT);\r
             if (mAccount != null) {\r
                 String ocVersion = mAccountMgr.getUserData(mAccount, AccountAuthenticator.KEY_OC_VERSION);\r
             mAccount = getIntent().getExtras().getParcelable(EXTRA_ACCOUNT);\r
             if (mAccount != null) {\r
                 String ocVersion = mAccountMgr.getUserData(mAccount, AccountAuthenticator.KEY_OC_VERSION);\r
@@ -218,12 +228,9 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
                 }\r
                 mHostBaseUrl = normalizeUrl(mAccountMgr.getUserData(mAccount, AccountAuthenticator.KEY_OC_BASE_URL));\r
                 mHostUrlInput.setText(mHostBaseUrl);\r
                 }\r
                 mHostBaseUrl = normalizeUrl(mAccountMgr.getUserData(mAccount, AccountAuthenticator.KEY_OC_BASE_URL));\r
                 mHostUrlInput.setText(mHostBaseUrl);\r
-                String userName = mAccount.name.substring(0, mAccount.name.lastIndexOf('@'));\r
-                mUsernameInput.setText(userName);\r
-                oAuthRequired = (mAccountMgr.getUserData(mAccount, AccountAuthenticator.KEY_SUPPORTS_OAUTH2) != null);\r
             }\r
             }\r
-            mOAuth2Check.setChecked(oAuthRequired);\r
-            changeViewByOAuth2Check(oAuthRequired);\r
+            initAuthorizationMethod();  // checks intent and setup.xml to determine mCurrentAuthorizationMethod\r
+            mOAuth2Check.setChecked(mCurrentAuthorizationMethod == AUTH_METHOD_OAUTH2);\r
             mJustCreated = true;\r
             \r
             if (mAction == ACTION_UPDATE_TOKEN || !mHostUrlInputEnabled) {\r
             mJustCreated = true;\r
             \r
             if (mAction == ACTION_UPDATE_TOKEN || !mHostUrlInputEnabled) {\r
@@ -252,6 +259,7 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
 \r
             // account data, if updating\r
             mAccount = savedInstanceState.getParcelable(KEY_ACCOUNT);\r
 \r
             // account data, if updating\r
             mAccount = savedInstanceState.getParcelable(KEY_ACCOUNT);\r
+            mCurrentAuthorizationMethod = savedInstanceState.getInt(KEY_AUTH_METHOD, AUTH_METHOD_BASIC_HTTP);\r
 \r
             // check if server check was interrupted by a configuration change\r
             if (savedInstanceState.getBoolean(KEY_SERVER_CHECK_IN_PROGRESS, false)) {\r
 \r
             // check if server check was interrupted by a configuration change\r
             if (savedInstanceState.getBoolean(KEY_SERVER_CHECK_IN_PROGRESS, false)) {\r
@@ -264,9 +272,10 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
 \r
         }\r
 \r
 \r
         }\r
 \r
+        adaptViewAccordingToAuthenticationMethod();\r
         showServerStatus();\r
         showAuthStatus();\r
         showServerStatus();\r
         showAuthStatus();\r
-\r
+        \r
         if (mAction == ACTION_UPDATE_TOKEN) {\r
             /// lock things that should not change\r
             mHostUrlInput.setEnabled(false);\r
         if (mAction == ACTION_UPDATE_TOKEN) {\r
             /// lock things that should not change\r
             mHostUrlInput.setEnabled(false);\r
@@ -280,7 +289,7 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
         if (mServerIsChecked && !mServerIsValid && refreshButtonEnabled) showRefreshButton();\r
         mOkButton.setEnabled(mServerIsValid); // state not automatically recovered in configuration changes\r
 \r
         if (mServerIsChecked && !mServerIsValid && refreshButtonEnabled) showRefreshButton();\r
         mOkButton.setEnabled(mServerIsValid); // state not automatically recovered in configuration changes\r
 \r
-        if (!OAUTH_MODE_OPTIONAL.equals(getString(R.string.oauth2_mode))) {\r
+        if (mCurrentAuthorizationMethod == AUTH_METHOD_SAML_WEB_SSO || !AUTH_OPTIONAL.equals(getString(R.string.auth_method_oauth2))) {\r
             mOAuth2Check.setVisibility(View.GONE);\r
         }\r
 \r
             mOAuth2Check.setVisibility(View.GONE);\r
         }\r
 \r
@@ -318,6 +327,43 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
         });
     }\r
 \r
         });
     }\r
 \r
+    private void initAuthorizationMethod() {\r
+        boolean oAuthRequired = false;\r
+        boolean samlWebSsoRequired = false;\r
+\r
+        String tokenType = getIntent().getExtras().getString(AccountAuthenticator.KEY_AUTH_TOKEN_TYPE);\r
+        mAccount = getIntent().getExtras().getParcelable(EXTRA_ACCOUNT);\r
+        \r
+        if (tokenType != null) {\r
+            /// use the authentication method requested by caller \r
+            oAuthRequired = AccountAuthenticator.AUTH_TOKEN_TYPE_ACCESS_TOKEN.equals(tokenType);\r
+            samlWebSsoRequired = AccountAuthenticator.AUTH_TOKEN_TYPE_SAML_WEB_SSO_SESSION_COOKIE.equals(tokenType);\r
+            \r
+        } else if (mAccount != null) {\r
+            /// same authentication method than the one used to create the account to update\r
+            oAuthRequired = (mAccountMgr.getUserData(mAccount, AccountAuthenticator.KEY_SUPPORTS_OAUTH2) != null);\r
+            samlWebSsoRequired = (mAccountMgr.getUserData(mAccount, AccountAuthenticator.KEY_SUPPORTS_SAML_WEB_SSO) != null);\r
+            \r
+        } else {\r
+            /// use the one set in setup.xml\r
+            oAuthRequired = AUTH_ON.equals(getString(R.string.auth_method_oauth2));\r
+            samlWebSsoRequired = AUTH_ON.equals(getString(R.string.auth_method_saml_web_sso));            \r
+        }\r
+        \r
+        if (oAuthRequired) {\r
+            mCurrentAuthorizationMethod = AUTH_METHOD_OAUTH2; \r
+        } else if (samlWebSsoRequired) {\r
+            mCurrentAuthorizationMethod = AUTH_METHOD_SAML_WEB_SSO;\r
+        } else {\r
+            mCurrentAuthorizationMethod = AUTH_METHOD_BASIC_HTTP;\r
+        }\r
+\r
+        if (mAccount != null) {\r
+            String userName = mAccount.name.substring(0, mAccount.name.lastIndexOf('@'));\r
+            mUsernameInput.setText(userName);\r
+        }\r
+    }\r
+\r
     /**\r
      * Saves relevant state before {@link #onPause()}\r
      * \r
     /**\r
      * Saves relevant state before {@link #onPause()}\r
      * \r
@@ -351,9 +397,9 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
         if (mAccount != null) {\r
             outState.putParcelable(KEY_ACCOUNT, mAccount);\r
         }\r
         if (mAccount != null) {\r
             outState.putParcelable(KEY_ACCOUNT, mAccount);\r
         }\r
+        outState.putInt(KEY_AUTH_METHOD, mCurrentAuthorizationMethod);\r
         \r
         // refresh button enabled\r
         \r
         // refresh button enabled\r
-        //outState.putBoolean(KEY_REFRESH_BUTTON_ENABLED, mRefreshButtonEnabled);\r
         outState.putBoolean(KEY_REFRESH_BUTTON_ENABLED, (mRefreshButton.getVisibility() == View.VISIBLE));\r
 \r
     }\r
         outState.putBoolean(KEY_REFRESH_BUTTON_ENABLED, (mRefreshButton.getVisibility() == View.VISIBLE));\r
 \r
     }\r
@@ -383,8 +429,6 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
     @Override\r
     protected void onResume() {\r
         super.onResume();\r
     @Override\r
     protected void onResume() {\r
         super.onResume();\r
-        // the state of mOAuth2Check is automatically recovered between configuration changes, but not before onCreate() finishes; so keep the next lines here\r
-        changeViewByOAuth2Check(mOAuth2Check.isChecked());  \r
         if (mAction == ACTION_UPDATE_TOKEN && mJustCreated && getIntent().getBooleanExtra(EXTRA_ENFORCED_UPDATE, false)) {\r
             if (mOAuth2Check.isChecked())\r
                 Toast.makeText(this, R.string.auth_expired_oauth_token_toast, Toast.LENGTH_LONG).show();\r
         if (mAction == ACTION_UPDATE_TOKEN && mJustCreated && getIntent().getBooleanExtra(EXTRA_ENFORCED_UPDATE, false)) {\r
             if (mOAuth2Check.isChecked())\r
                 Toast.makeText(this, R.string.auth_expired_oauth_token_toast, Toast.LENGTH_LONG).show();\r
@@ -1259,33 +1303,54 @@ implements  OnRemoteOperationListener, OnSslValidatorListener, OnFocusChangeList
      * @param view      'View password' 'button'\r
      */\r
     public void onCheckClick(View view) {\r
      * @param view      'View password' 'button'\r
      */\r
     public void onCheckClick(View view) {\r
-        CheckBox oAuth2Check = (CheckBox)view;      \r
-        changeViewByOAuth2Check(oAuth2Check.isChecked());\r
-\r
+        CheckBox oAuth2Check = (CheckBox)view;\r
+        if (oAuth2Check.isChecked()) {\r
+            mCurrentAuthorizationMethod = AUTH_METHOD_OAUTH2;\r
+        } else {\r
+            mCurrentAuthorizationMethod = AUTH_METHOD_BASIC_HTTP;\r
+        }\r
+        adaptViewAccordingToAuthenticationMethod();\r
     }\r
 \r
     }\r
 \r
+    \r
     /**\r
     /**\r
-     * Changes the visibility of input elements depending upon the kind of authorization\r
-     * chosen by the user: basic or OAuth\r
-     * \r
-     * @param checked       'True' when OAuth is selected.\r
+     * Changes the visibility of input elements depending on\r
+     * the current authorization method.\r
      */\r
      */\r
-    public void changeViewByOAuth2Check(Boolean checked) {\r
-\r
-        if (checked) {\r
-            mOAuthAuthEndpointText.setVisibility(View.VISIBLE);\r
-            mOAuthTokenEndpointText.setVisibility(View.VISIBLE);\r
-            mUsernameInput.setVisibility(View.GONE);\r
-            mPasswordInput.setVisibility(View.GONE);\r
-        } else {\r
-            mOAuthAuthEndpointText.setVisibility(View.GONE);\r
-            mOAuthTokenEndpointText.setVisibility(View.GONE);\r
-            mUsernameInput.setVisibility(View.VISIBLE);\r
-            mPasswordInput.setVisibility(View.VISIBLE);\r
-        }     \r
-\r
-    }    \r
-\r
+    private void adaptViewAccordingToAuthenticationMethod () {\r
+        switch (mCurrentAuthorizationMethod) { \r
+            case AUTH_METHOD_OAUTH2:\r
+                // OAuth 2 authorization\r
+                mOAuthAuthEndpointText.setVisibility(View.VISIBLE);\r
+                mOAuthTokenEndpointText.setVisibility(View.VISIBLE);\r
+                mUsernameInput.setVisibility(View.GONE);\r
+                mPasswordInput.setVisibility(View.GONE);\r
+                mAccountNameInput.setVisibility(View.GONE);\r
+                mWebSsoView.setVisibility(View.GONE);\r
+                break;\r
+                \r
+            case AUTH_METHOD_SAML_WEB_SSO:\r
+                // SAML-based web Single Sign On\r
+                mOAuthAuthEndpointText.setVisibility(View.GONE);\r
+                mOAuthTokenEndpointText.setVisibility(View.GONE);\r
+                mUsernameInput.setVisibility(View.GONE);\r
+                mPasswordInput.setVisibility(View.GONE);\r
+                mAccountNameInput.setVisibility(View.VISIBLE);\r
+                mWebSsoView.setVisibility(View.VISIBLE);\r
+                break;\r
+                \r
+            case AUTH_METHOD_BASIC_HTTP:\r
+            default:\r
+                // basic HTTP authorization\r
+                mOAuthAuthEndpointText.setVisibility(View.GONE);\r
+                mOAuthTokenEndpointText.setVisibility(View.GONE);\r
+                mUsernameInput.setVisibility(View.VISIBLE);\r
+                mPasswordInput.setVisibility(View.VISIBLE);\r
+                mAccountNameInput.setVisibility(View.GONE);\r
+                mWebSsoView.setVisibility(View.GONE);\r
+            }\r
+    }\r
+    \r
     /**\r
      * Called from SslValidatorDialog when a new server certificate was correctly saved.\r
      */\r
     /**\r
      * Called from SslValidatorDialog when a new server certificate was correctly saved.\r
      */\r