Skip to content

Commit 5f6b078

Browse files
author
Ioannis Kakavas
committed
Ensure signature checking for SAML Responses is enabled by default
1 parent 5d7f27e commit 5f6b078

File tree

2 files changed

+3
-4
lines changed

2 files changed

+3
-4
lines changed

src/saml2/client_base.py

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -112,10 +112,9 @@ def __init__(self, config=None, identity_cache=None, state_cache=None,
112112
self.allow_unsolicited = False
113113
self.authn_requests_signed = False
114114
self.want_assertions_signed = False
115-
self.want_response_signed = False
115+
self.want_response_signed = True
116116
for foo in ["allow_unsolicited", "authn_requests_signed",
117-
"logout_requests_signed", "want_assertions_signed",
118-
"want_response_signed"]:
117+
"logout_requests_signed", "want_assertions_signed"]:
119118
v = self.config.getattr(foo, "sp")
120119
if v is True or v == 'true':
121120
setattr(self, foo, True)

src/saml2/response.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -470,7 +470,7 @@ def __init__(self, sec_context, attribute_converters, entity_id,
470470
return_addrs=None, outstanding_queries=None,
471471
timeslack=0, asynchop=True, allow_unsolicited=False,
472472
test=False, allow_unknown_attributes=False,
473-
want_assertions_signed=False, want_response_signed=False,
473+
want_assertions_signed=False, want_response_signed=True,
474474
conv_info=None, **kwargs):
475475

476476
StatusResponse.__init__(self, sec_context, return_addrs, timeslack,

0 commit comments

Comments
 (0)