From abc947c7883b194b179be0afa25f40a4b47c31e0 Mon Sep 17 00:00:00 2001 From: Olav Morken <olav.morken@uninett.no> Date: Tue, 9 Aug 2011 06:25:34 +0000 Subject: [PATCH] docs: Clarify the IdP initiated authentication documentation slightly. - Fix the entityID in the example URL to be a valid entityID. - Clarify the difference between `TARGET` in authentication response vs. `target` in authentication "request". git-svn-id: https://simplesamlphp.googlecode.com/svn/trunk@2884 44740490-163a-0410-bde0-09ae8108e29a --- docs/simplesamlphp-idp-more.txt | 6 ++++-- modules/saml/docs/sp.txt | 4 +++- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/docs/simplesamlphp-idp-more.txt b/docs/simplesamlphp-idp-more.txt index 25fcaf049..60d2c4626 100644 --- a/docs/simplesamlphp-idp-more.txt +++ b/docs/simplesamlphp-idp-more.txt @@ -46,7 +46,7 @@ If you do not want to start the SSO flow at the SP, you may use the IdP-first se Here is an example of such an url: - https://idp.example.org/simplesaml/saml2/idp/SSOService.php?spentityid=dev.andreas.feide.no + https://idp.example.org/simplesaml/saml2/idp/SSOService.php?spentityid=urn:mace:feide.no:someservice You can also add a RelayState parameter to the IdP-first URL: @@ -73,10 +73,12 @@ The parameters are as follows: This parameter is required. `target` -: The target parameter the SP should receive. +: The target parameter the SP should receive with the authentication response. This is often the page the user should be sent to after authentication. This parameter is optional for the IdP, but must be specified if the SP you are targeting is running simpleSAMLphp SP. +: *Note*: This parameter must be sent as `target` (with lowercase letters) when starting the authentication, while it is sent as `TARGET` (with uppercase letters) in the authentication response. + IdP-initiated logout -------------------- diff --git a/modules/saml/docs/sp.txt b/modules/saml/docs/sp.txt index be2d7de7b..90b1f0dab 100644 --- a/modules/saml/docs/sp.txt +++ b/modules/saml/docs/sp.txt @@ -319,7 +319,9 @@ Options : The page the user should be redirected to after an IdP initiated SSO. : *Note*: SAML 2 specific. - For SAML 1.1 SPs, you must specify the `TARGET` in the authentication response. + For SAML 1.1 SPs, you must specify the `TARGET` parameter in the authentication response. + How to set that parameter is depends on the IdP. + For simpleSAMLphp, see the documentation for [IdP-first flow](./simplesamlphp-idp-more#section_4_1). `url` : An URL to your service provider. Will be added as an OrganizationURL-element in the metadata. -- GitLab