JSON dictionary in the Relay State parameter
Florian Lengyel
Florian.Lengyel at cuny.edu
Sun Mar 24 04:32:29 UTC 2024
"If you want to go to these 2 vendors and ask them to fix something, that seems the more bulletproof approach. But see below for the actual requirements. JSON - encoded or not - is quite possibly too large."
In the SAML 2.0 Errata 05, the guidelines regarding RelayState sanitization are presented as requirements, not just recommendations. Implementations must carefully sanitize the URL schemes they permit, specifically restricting them to "http" or "https" and must disallow unencoded characters that could lead to security attacks
Have these requirements been relaxed to recommendations?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240324/671af4b1/attachment.htm>
More information about the users
mailing list