spring-projects / spring-projects/spring-security

Saml2 support overriding the SAMLRequest parameters

Open
#9,199 14 comments 0 reactions 1 assignee View on GitHub

@jzheaux is already working on this.

Since Nov 11, 2020.

in: saml2 type: enhancement
Dominant language
Java
Stars
9.6k
Forks
6.3k
Avg merge
2d 11h
Merged PRs (30d)
52

Description

Expected Behavior
As a service provider, it would be great if we could override the following parameter in a SAMLRequest

  • saml:AuthnContextClassRef
  • ForceAuthn
  • IsPassive

Current Behavior
Currently, we are having the default values configured which is

Context
As a service provider, we want to enforce the user is always prompted for authentication while access some sensitive service so we would like to set the following values.

saml:AuthnContextClassRef = urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
ForceAuthn =true

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.