You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A SAML response comes back with a signature and the certificate used to generate that signature. When invoking the library, we pass a cert in options that specifies the key that we expect to have been used in creating the signature.
If the certificate that comes back in the SAML response does not match the cert option that is passed, it would be nice to have separately error-handling that provides a descriptive error. Although the current behavior is not wrong (in that it throws an error because the signature is invalid), it would be nice to have a more descriptive error message in this particular case.