samly v1.0.0 Release Notes
Release Date: 2019-03-12 // about 6 years ago-
target_url
query parameter for the sign-in/sign-out requests must bex-www-form-urlencoded
.Redirect URLs are properly encoded.
๐ Switched to
report-to
in content security policy.โก๏ธ
cache-control
header value updated.๐ Issue: #33 - Content Security Policy Enabled
Content-Security-Policy
in the HTTP response.๐ PR: #41 - Config support for nameid format
Samly
uses the nameid format from the IdP metadata XML file. It is possible now to override this usingnameid_fomat
config setting. If this format information is not present in the IdP metadata XML and not specified in the config setting, it defaults to:transient
. Thanks to calvinb for the PR.๐ Uptake
esaml 4.2
bringing in support for encrypted assertions. Check Assertion Encryption for supported encryption algorithms. Use this information to enable assertion encryption on IdP. Thanks to tcrossland for theesaml
PR.