Skip to content

Add support for decrypting EncryptedIDs#238

Open
flupzor wants to merge 4 commits into
SAML-Toolkits:masterfrom
maykinmedia:pr-encrypted-ids-rebased
Open

Add support for decrypting EncryptedIDs#238
flupzor wants to merge 4 commits into
SAML-Toolkits:masterfrom
maykinmedia:pr-encrypted-ids-rebased

Conversation

@flupzor

@flupzor flupzor commented Jan 28, 2021

Copy link
Copy Markdown
Contributor

This PR adds support for decrypting Responses which include EncryptedIDs in the AttributeStatement/Attribute section.

@pitbulk

pitbulk commented Jan 28, 2021

Copy link
Copy Markdown
Contributor

Not a common scenario to have EncryptedIDs instead the whole assertion encrypted, but something to review and merge.
Thanks

@flupzor flupzor force-pushed the pr-encrypted-ids-rebased branch from 9a01a84 to 08bcfd0 Compare February 25, 2021 13:51
@flupzor

flupzor commented Feb 25, 2021

Copy link
Copy Markdown
Contributor Author

I removed a commit which changed the behavior of 'validate_num_assertions'. I messed up and it should've been part of #247 and as @pitbulk pointed out, ignoring the Advice element can allow XML signature wrapping attacks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants