<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<br>
<div class="moz-cite-prefix">On 04/15/2025 5:56 PM, Steven Teixeira
via users wrote:<br>
</div>
<blockquote type="cite"
cite="mid:SJ0PR17MB45115719D36A5482CEFE0440A1B22@SJ0PR17MB4511.namprd17.prod.outlook.com">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta name="Generator"
content="Microsoft Word 15 (filtered medium)">
<style>@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}@font-face
{font-family:Aptos;}p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:12.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;}a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#467886;
text-decoration:underline;}span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Aptos",sans-serif;
color:windowtext;}.MsoChpDefault
{mso-style-type:export-only;}div.WordSection1
{page:WordSection1;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt">A new
install of IdP v5.1.4 shows a new property in idp.properties
named “idp.http.saml.enforceAllowedParameters” but I can’t
seem to find any documentation of this property, even at
<a
href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199510693/PropertyReference"
moz-do-not-send="true" class="moz-txt-link-freetext">
https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199510693/PropertyReference</a>.
Was this a property for a future, unreleased version that
somehow made its way into 5.1.4?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span><br>
</p>
</div>
</blockquote>
<br>
Given my current documentation assessment, I went looking as well --
I can not find documentation on this new setting (other that the <a
href="https://git.shibboleth.net/view/?p=java-identity-provider.git;a=commitdiff;h=55c6445c633a6397499809b363995e2e32593895">git
commit</a>).<br>
<br>
The idp.properties comment is:<br>
<blockquote type="cite">Set true if you want inbound SAML requests
to enforce that only allowed HTTP parameters are present</blockquote>
The default is false (enforcement disabled), matching previous
behavior.<br>
<br>
I'll defer to others on what might need to be considered before
enabling this enforcement, but (as is typically the case) the
default setting should preserve the behavior prior to the upgrade.<br>
<br>
Steve.<br>
<br>
<i>Please consider completing the <a
href="https://forms.gle/UrU1h4X5po1CsfB7A">IDP documentation
survey</a>, if you have not already done so.</i><br>
</body>
</html>