Comments (5)
@yesvivek we should replace this line https://github.com/auth0/node-samlp/blob/master/lib/samlp.js#L52 with something like this:
sig.computeSignature(cannonicalized, { prefix: options.signatureNamespacePrefix, location: { action: 'after', reference: "//*[local-name(.)='Issuer']" }});
I'll send an update to the library with some tests later this week.
from node-samlp.
v3.3.2 published
from node-samlp.
@yesvivek no, sorry. I see that there are two PRs open for this. I have requested some changes + tests. I'll let you know when this is fixed
from node-samlp.
@mcastany That change is all needed, works good now. Thanks a lot!
from node-samlp.
Not sure whether this is fixed already or not. @mcastany could you please confirm.
from node-samlp.
Related Issues (20)
- Missing saml: prefix on Issuer and NameID tags in LogoutRequest HOT 1
- redirectEndpointPath documentation HOT 1
- 401 improvement HOT 1
- SAML assertion signing using HSM
- NPM Release for 3.4.2? HOT 1
- Can I get an example code
- update xml-crypto dependency HOT 3
- Update saml dependency HOT 1
- Current backwards compatability checks are preventing dependencies from being updated. HOT 2
- Math.random() is not cryptographically secure HOT 1
- Add Organization Details to samlp.metadata
- Request for help
- Dynamically Set Audience
- Uncaught Exception Error in samlp.logout
- Update xml-crypto dependency to solve npm audit issue 1769 HOT 1
- Found Vulnerability ' Improper Input Validation ' and ' Prototype Pollution ' on Synk.io HOT 3
- Npm audit advisories found HOT 1
- Dependency querystring is deprecated. URLSearchParams API should be used instead HOT 1
- Function is not defined error HOT 1
- Request for upgrading the ejs package to the patched version 3.1.10
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from node-samlp.