Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[fix] Allow IdP set reference ID for SAML response #21

Merged
merged 4 commits into from
Oct 25, 2024

Conversation

Zogoo
Copy link
Owner

@Zogoo Zogoo commented Oct 23, 2024

SAML SLO requests can be received via XHR directly by the IDP. In this case, browser session data won’t be shared through an iframe or a direct server-to-server POST request. However, the IdP needs to know which session is being terminated using the SessionIndex in the SLO request, originally provided in the SAML response (reference ID). For this reason, the IDP should set the reference ID.

@Zogoo Zogoo self-assigned this Oct 23, 2024
@Zogoo Zogoo changed the title [fix] Pass ref id as Session Index [fix] Allow IdP set reference ID for SAML response Oct 23, 2024
@Zogoo Zogoo merged commit fcb331b into master Oct 25, 2024
25 checks passed
Zogoo added a commit that referenced this pull request Nov 5, 2024
* Squash commits for saml_idp gem

* [feat] Allow SP config force signature validation (#16)

* Allow SP config force signature validation

* Allow SP config force signature validation

Tested with Slack with Authn request signature option
---------

Co-authored-by: zogoo <[email protected]>

* [feat] Don’t ignore certificates without usage (#17)

I have tested with live SAML SP apps and it works fine

* Unspecified certifciate from SP metadata

---------

Co-authored-by: zogoo <[email protected]>

* Try with proper way to update helper method (#19)

* Set minimum test coverage (saml-idp#207)

* Set minimum test coverage to a very high value for testing

* Update minimum coverage to actual current value

* Try with proper way to update helper method

* Correctly decode and mock with correct REXML class

* Drop the min coverage

---------

Co-authored-by: Mathieu Jobin <[email protected]>
Co-authored-by: zogoo <[email protected]>

* [feat] Collect request validation errors (#18)

* wip add error collector

* Fix type and rewrite request with proper validation test cases

* Lead error render decision to gem user

* Validate the certificate's existence before verifying the signature.

---------

Co-authored-by: zogoo <[email protected]>

* Support lowercase percent-encoded sequences for URL encoding (#20)

Co-authored-by: zogoo <[email protected]>

* Pass ref id as Session Index

* Official Rails 8 is not released yet to RubyGem until that let's stick official older version

* [fix] Gem CI updates for latest versions (#22)

* Remove duplications

* Pre-conditions need to be defined in before section

* Le's not test logger in here

---------

Co-authored-by: zogoo <[email protected]>

* [fix] Allow IdP set reference ID for SAML response (#21)

* Pass ref id as Session Index

* Official Rails 8 is not released yet to RubyGem until that let's stick official older version

---------

Co-authored-by: zogoo <[email protected]>

* Fixes for ORIGIN gem

---------

Co-authored-by: zogoo <[email protected]>
Co-authored-by: Mathieu Jobin <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant