New undocumented property in IdP v5.1.4
Steven Premeau
shibboleth at premeauenterprises.com
Tue Apr 15 22:43:03 UTC 2025
On 04/15/2025 5:56 PM, Steven Teixeira via users wrote:
>
> A new install of IdP v5.1.4 shows a new property in idp.properties named
> “idp.http.saml.enforceAllowedParameters” but I can’t seem to find any
> documentation of this property, even at
> https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199510693/PropertyReference.
> Was this a property for a future, unreleased version that somehow made its
> way into 5.1.4?
>
>
Given my current documentation assessment, I went looking as well -- I can not
find documentation on this new setting (other that the git commit
<https://git.shibboleth.net/view/?p=java-identity-provider.git;a=commitdiff;h=55c6445c633a6397499809b363995e2e32593895>).
The idp.properties comment is:
> Set true if you want inbound SAML requests to enforce that only allowed HTTP
> parameters are present
The default is false (enforcement disabled), matching previous behavior.
I'll defer to others on what might need to be considered before enabling this
enforcement, but (as is typically the case) the default setting should
preserve the behavior prior to the upgrade.
Steve.
/Please consider completing the IDP documentation survey
<https://forms.gle/UrU1h4X5po1CsfB7A>, if you have not already done so./
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250415/596a9e94/attachment.htm>
More information about the users
mailing list