Santuario change

Cantor, Scott cantor.2 at osu.edu
Thu Nov 5 10:03:17 EST 2015


On 11/5/15, 2:55 AM, "dev on behalf of Brent Putman" <dev-bounces at shibboleth.net on behalf of putmanb at georgetown.edu> wrote:



>As I mentioned, we already have similar issues with decryption+validation (e.g. decrypt an Assertion then validate its signature).  That is documented extensively in the Decrypter Javadocs.  This may just have to be a documentation thing.

It's fairly easy to trigger in a unit test. Do we want to do anything to cover this case? I guess maybe not, but it felt weird since it obviously changed behavior with 2.0.5 and our tests didn't notice. But a test here would just fail so it would be an inverse test to verify that the library contained to fail on this case I guess. Feels like we should have something.

-- Scott



More information about the dev mailing list