Skip to content
Snippets Groups Projects
  1. Nov 20, 2018
  2. Oct 17, 2018
  3. Aug 22, 2018
  4. Aug 13, 2018
  5. Oct 19, 2017
  6. Aug 14, 2017
    • Jan de Mooij's avatar
      Make POST template compatible with CSP (#635) · 9c49e503
      Jan de Mooij authored
      See issue #593 for a problem description.
      SimpleSamlPHP makes use of unsafe inline Javascript and CSS elements.
      Although most generated HTML uses SimpleSamlPHP's own headers, the
      keepPost option in an authentication request uses the headers of
      the PHP application it is sent from. This forces web applications
      using SimpleSamlPHP to allow 'unsafe-inline' in their Content
      Security Policy.
      
      This commit fixes this issue for the keepPost page ''only'', to
      allow PHP applications using SimpleSamlPHP to use a more strict
      Content Security Policy. This does not take away from possible
      XSS vulnerabilities in other parts of SimpleSamlPHP.
      9c49e503
  7. Nov 06, 2015
  8. Jan 27, 2012
  9. Jan 11, 2011
  10. Jul 03, 2009
  11. Jan 26, 2009
  12. Mar 26, 2008
  13. Dec 14, 2007
  14. Oct 20, 2007
  15. Sep 14, 2007
Loading