Santuario change
Cantor, Scott
cantor.2 at osu.edu
Thu Nov 5 10:03:17 EST 2015
On 11/5/15, 2:55 AM, "dev on behalf of Brent Putman" <dev-bounces at shibboleth.net on behalf of putmanb at georgetown.edu> wrote:
>As I mentioned, we already have similar issues with decryption+validation (e.g. decrypt an Assertion then validate its signature). That is documented extensively in the Decrypter Javadocs. This may just have to be a documentation thing.
It's fairly easy to trigger in a unit test. Do we want to do anything to cover this case? I guess maybe not, but it felt weird since it obviously changed behavior with 2.0.5 and our tests didn't notice. But a test here would just fail so it would be an inverse test to verify that the library contained to fail on this case I guess. Feels like we should have something.
-- Scott
More information about the dev
mailing list