<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<span style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">The interpretation provided in your message that E90 only applies when the RelayState value is a URL is indeed not
 entirely accurate according to the text from the SAML 2.0 Errata E90. The errata do emphasize concerns around URLs because they're common and high-risk vectors for attacks such as XSS (Cross-Site Scripting) and CSRF (Cross-Site Request Forgery), but the caution
 is broader.</span>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Here's a breakdown:</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
1. Sanitization and Security Concerns: The errata indicates that there's a need for careful sanitization due to the lack of "end-to-end origin authentication or integrity protection of the RelayState value." This concern applies broadly to the handling of RelayState,
 not exclusively to situations where RelayState is a URL.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
2. Implementation Guidance: The guidance to "carefully sanitize the URL schemes they permit" and "disallow unencoded characters that may be used in mounting such attacks" suggests a focus on URLs, but the underlying principle is to prevent the RelayState from
 being exploited for attacks. This principle should apply to any content within RelayState that could be manipulated for malicious purposes.</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
3. URL-Specific Advice: While the text emphasizes URL schemes (restricting them to "http" or "https") and the prevention of executable content, the broader context of these guidelines is the prevention of XSS and CSRF attacks. This does not exclude other forms
 of data from being a concern if they can similarly be exploited due to improper handling or lack of sanitization.</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
4. Broader Application: The mention that "implementations MUST carefully sanitize...and should disallow unencoded characters" indicates a broader requirement than just for URLs. It suggests that any data within the RelayState should be handled in a way that
 prevents malicious exploitation, which would include ensuring that JSON structures or other data forms don't contain harmful content.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
The intention is that all data, including but not limited to URLs, passed in the RelayState should be sanitized and secured against common web vulnerabilities. The errata's references to URL schemes and encoding primarily address the most common risks but do
 not limit the scope of sanitization to URLs alone.</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Therefore, asserting that the standard's requirements for sanitizing RelayState apply only to URLs and not to other data formats like JSON is misinterpretation of the errata. It's critical for all transmitted data, regardless of format, to be secured against
 potential web-based vulnerabilities, especially in authentication flows.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div style="direction: ltr; font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<b>From:</b> users <users-bounces@shibboleth.net> on behalf of Brent Putman via users <users@shibboleth.net><br>
<b>Sent:</b> Sunday, March 24, 2024 3:26 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Brent Putman <putmanb@georgetown.edu><br>
<b>Subject:</b> Re: JSON dictionary in the Relay State parameter</div>
<div style="direction: ltr;"> </div>
<div style="background-color: rgb(255, 252, 213); margin: 2em; border-width: 1px; border-style: solid; border-color: initial;">
<p style="text-align: center; padding: 1em;"><b>* This email originates from a sender outside of CUNY. Verify the sender before replying or clicking on links and attachments. *</b></p>
</div>
<p><br>
</p>
<div>On 3/24/24 12:32 AM, Florian Lengyel via users wrote:</div>
<blockquote>
<div style="direction: ltr;"><br>
</div>
<p style="direction: ltr;">In the SAML 2.0 Errata 05, the guidelines regarding RelayState sanitization are presented as requirements, not just recommendations. Implementations must carefully sanitize the URL schemes they permit, specifically restricting them
 to "http" or "https" and must disallow unencoded characters that could lead to security attacks </p>
<div style="direction: ltr;">Have these requirements been relaxed to recommendations?</div>
<br>
</blockquote>
<p><br>
</p>
<p>No, Errata 05 is still the latest.  However, I believe what you are referring to in E90 there doesn't actually apply in your case of a JSON value.  It only addresses the case where the RelayState value is a URL (which is somewhat common in the real world).
 Essentially, IF it is a URL, THEN it must have an http or https scheme only and be encoded appropriately to address XSS, CSRF and other attacks, etc. </p>
</body>
</html>