Policy wasn't receiving access to HTTP request so as to check Recipient values in assertions.

Description

The SAML 2 profile handler wasn't checking the subject confirmation's Recipient attribute because of an error in the policy evaluation step. Audience was still checked, and a separate bug prevented unsigned responses from working properly anyway, so there's little or no security impact at this point.

Environment

None

Activity

Show:

Scott Cantor June 23, 2009 at 12:47 PM

Closing after releases.

Fixed
Pinned fields
Click on the next to a field label to start pinning.

Details

Assignee

Reporter

Fix versions

Affects versions

Created April 20, 2009 at 2:17 PM
Updated June 23, 2009 at 12:47 PM
Resolved April 20, 2009 at 2:17 PM

Flag notifications