Skip to content

providers/saml: fix invalid SAML Response when assertion and response are signed (cherry-pick #12611)#12613

Merged
BeryJu merged 1 commit intoversion-2024.12from
cherry-pick-1fd640-version-2024.12
Jan 9, 2025
Merged

providers/saml: fix invalid SAML Response when assertion and response are signed (cherry-pick #12611)#12613
BeryJu merged 1 commit intoversion-2024.12from
cherry-pick-1fd640-version-2024.12

Conversation

@gcp-cherry-pick-bot
Copy link
Contributor

Cherry-picked providers/saml: fix invalid SAML Response when assertion and response are signed (#12611)

  • providers/saml: fix invalid SAML Response when assertion and response are signed

Signed-off-by: Jens Langhammer jens@goauthentik.io

  • validate against schema too

Signed-off-by: Jens Langhammer jens@goauthentik.io


Signed-off-by: Jens Langhammer jens@goauthentik.io

… are signed (#12611)

* providers/saml: fix invalid SAML Response when assertion and response are signed

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

* validate against schema too

Signed-off-by: Jens Langhammer <jens@goauthentik.io>

---------

Signed-off-by: Jens Langhammer <jens@goauthentik.io>
@gcp-cherry-pick-bot gcp-cherry-pick-bot bot requested a review from a team as a code owner January 9, 2025 15:20
@BeryJu BeryJu merged commit cbe429f into version-2024.12 Jan 9, 2025
@BeryJu BeryJu deleted the cherry-pick-1fd640-version-2024.12 branch January 9, 2025 15:20
@netlify
Copy link

netlify bot commented Jan 9, 2025

Deploy Preview for authentik-docs ready!

Name Link
🔨 Latest commit e1ec547
🔍 Latest deploy log https://app.netlify.com/sites/authentik-docs/deploys/677fe94b864eef0008d2a7d8
😎 Deploy Preview https://deploy-preview-12613--authentik-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site configuration.

@codecov
Copy link

codecov bot commented Jan 9, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 92.72%. Comparing base (1cf0f57) to head (e1ec547).
Report is 1 commits behind head on version-2024.12.

✅ All tests successful. No failed tests found.

Additional details and impacted files
@@                 Coverage Diff                 @@
##           version-2024.12   #12613      +/-   ##
===================================================
- Coverage            92.78%   92.72%   -0.06%     
===================================================
  Files                  770      770              
  Lines                38777    38789      +12     
===================================================
- Hits                 35980    35969      -11     
- Misses                2797     2820      +23     
Flag Coverage Δ
e2e 48.65% <15.38%> (-0.07%) ⬇️
integration 24.61% <0.00%> (-0.01%) ⬇️
unit 90.39% <100.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@github-actions
Copy link
Contributor

github-actions bot commented Jan 9, 2025

authentik PR Installation instructions

Instructions for docker-compose

Add the following block to your .env file:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-e1ec547aed3b88c759837d792d113133368db36a
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

For arm64, use these values:

AUTHENTIK_IMAGE=ghcr.io/goauthentik/dev-server
AUTHENTIK_TAG=gh-e1ec547aed3b88c759837d792d113133368db36a-arm64
AUTHENTIK_OUTPOSTS__CONTAINER_IMAGE_BASE=ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s

Afterwards, run the upgrade commands from the latest release notes.

Instructions for Kubernetes

Add the following block to your values.yml file:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-e1ec547aed3b88c759837d792d113133368db36a

For arm64, use these values:

authentik:
    outposts:
        container_image_base: ghcr.io/goauthentik/dev-%(type)s:gh-%(build_hash)s
global:
    image:
        repository: ghcr.io/goauthentik/dev-server
        tag: gh-e1ec547aed3b88c759837d792d113133368db36a-arm64

Afterwards, run the upgrade commands from the latest release notes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant