sources/saml: prevent authnrequest signature being inside body on redirect#19898
sources/saml: prevent authnrequest signature being inside body on redirect#19898PeshekDotDev merged 4 commits intomainfrom
Conversation
✅ Deploy Preview for authentik-integrations ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview for authentik-storybook ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
47cd865 to
2b60997
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #19898 +/- ##
==========================================
+ Coverage 93.21% 93.24% +0.02%
==========================================
Files 968 968
Lines 53438 53567 +129
==========================================
+ Hits 49813 49946 +133
+ Misses 3625 3621 -4
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
✅ Deploy Preview for authentik-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
90c1871 to
aba0ba5
Compare
…ntik into authnrequest-signature
|
authentik PR Installation instructions Instructions for docker-composeAdd the following block to your AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-bb78d73713645b00dab75cb5d88562329eda5b29
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)sAfterwards, run the upgrade commands from the latest release notes. Instructions for KubernetesAdd the following block to your authentik:
outposts:
container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
image:
repository: ghcr.io/goauthentik/dev-server
tag: gh-bb78d73713645b00dab75cb5d88562329eda5b29Afterwards, run the upgrade commands from the latest release notes. |
Details
When sending an authnrequest, the signature must go inside of the url parameter. The body cannot be signed, as this can effect the xml size, the signatures will not match each other in the url and the saml body, and some idp's can have parsing errors due to not expecting this in the body
Checklist
ak test authentik/)make lint-fix)If an API change has been made
make gen-build)If changes to the frontend have been made
make web)If applicable
make docs)