<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body>
<div dir="auto"><br>
</div>
<div id="mail-editor-reference-message-container" dir="auto">
<div dir="auto">
<div id="mail-editor-reference-message-container" dir="auto">
<div dir="auto">"If you want to go to these 2 vendors and ask them to fix something, that seems the more bulletproof approach. But see below for the actual requirements. JSON - encoded or not - is quite possibly too large."<br>
</div>
<div dir="auto">
<p>In the SAML 2.0 Errata 05, the guidelines regarding RelayState sanitization are presented as requirements, not just recommendations. Implementations must carefully sanitize the URL schemes they permit, specifically restricting them to "http" or "https" and
must disallow unencoded characters that could lead to security attacks </p>
<div dir="auto">Have these requirements been relaxed to recommendations?</div>
</div>
</div>
</div>
<br>
</div>
</body>
</html>