Skip to content
Snippets Groups Projects
  1. Sep 16, 2016
  2. Sep 15, 2016
  3. Sep 14, 2016
  4. Sep 07, 2016
  5. Sep 06, 2016
  6. Sep 05, 2016
  7. Aug 31, 2016
  8. Aug 30, 2016
  9. Aug 25, 2016
  10. Aug 23, 2016
  11. Aug 22, 2016
  12. Aug 17, 2016
  13. Aug 16, 2016
  14. Aug 15, 2016
    • Jaime Pérez's avatar
      Multiple enhancements and fixes to IDPList support in proxy mode. · c70e0b75
      Jaime Pérez authored
      - Bugfix: the modules/saml/www/proxy/invalid_session.php shouldn't call directly the error handler in sspmod_saml_IdP_SAML2. Instead, it should use the SimpleSAML_Auth_State::throwException() method to let it handle the exception appropriately (in this case, it should always return back to the requester).
      - The standard specifies that a "urn:oasis:names:tc:SAML:2.0:status:NoSupportedIDP" or "urn:oasis:names:tc:SAML:2.0:status:NoAvailableIDP" second-level status code should be returned to the requester in case an error occurs. Add a couple of exceptions to represent both statuses, and use them to set the right status code in the response.
      - We shouldn't ask the user to logout in case the IDPList does not offer an IdP we recognize, or in case the proxy enforces the use of an IdP ('idp' configuration option in the auth source) and such IdP is in the IDPList.
      - Similarly, these two cases should also handled in case we are authenticating for the first time, not only when reauthenticating.
      c70e0b75
Loading