AssertionConsumerServiceURL mismatch between Request and configured metadata is handled too gracefully
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Stack tecnologico
- php
- Ambito
- authentication, security
Direzione di ricerca
Inizia individuando la gestione di AuthNRequest e il controllo che seleziona una AssertionConsumerServiceURL dalla richiesta o dai metadati configurati. Riproduci una richiesta non firmata la cui AssertionConsumerServiceURL sia assente dai metadati, quindi verifica che generi un errore di protocollo fatale, mentre le richieste firmate e i metadati corrispondenti continuano a funzionare.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Specifics of your environment
- simpleSAMLphp is an IdP
- SimpleSAMLphp version is 2.5.2
- PHP is version 8.3
- Platform is Linux
- Webserver is an nginx frontend with FPM backend
Describe the bug
If a SAML SP sends an AuthNRequest with the optional parameter AssertionConsumerServiceURL, and that URL is not contained in the SP configured metadata, and the request is not signed, then authentication succeeds and SSP sends the assertion back to one of the URLs from metadata.
However, the SAML spec states
AssertionConsumerServiceURL [Optional]
Specifies by value the location to which the message MUST be returned to the
requester. The responder MUST ensure by some means that the value specified is in fact associated
with the requester.
One way is signed requests - in this case it is okay to continue the authentication and take the received AssertionConsumerServiceURL at face value.
Another way is pre-configured metadata. In that case, a mismatch is a problem.
Expected behavior
In the given situation (unsigned request, stored metadata with different ACS URLs), it is impossible to satisfy both MUST conditions simultaneously; one of the two is always violated. A protocol violation should not lead to successful auth, but raise a fatal protocol error instead.
- Lingua principale
- PHP
- Stelle
- 1.1k
- Fork
- 704
- Merge medio
- 1g 15h
- PR unite (30g)
- 4
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di simplesamlphp/simplesamlphp
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 74/100
simplesamlphp/simplesamlphp#2684 ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
simplesamlphp/simplesamlphp#2683 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
simplesamlphp/simplesamlphp#2674 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
simplesamlphp/simplesamlphp#2673 · 1 commento ·
-
Confirmed enhancement
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
simplesamlphp/simplesamlphp#2664 · 2 commenti ·
Tutte le issue di simplesamlphp/simplesamlphp
Issue simili
-
sync-en
Difficoltà 1/5 1-3 ore Idoneità per principianti 85/100
-
sync-en
Difficoltà 1/5 1-3 ore Idoneità per principianti 85/100
-
Перевод устарел
Difficoltà 1/5 1-3 ore Idoneità per principianti 78/100
-
[6.x]: "Cannot use object of type stdClass as array" loading Users index (regression of #19182) Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100