Skip to content

Conversation

@lucasmrod
Copy link

@lucasmrod lucasmrod commented Apr 17, 2025

Hi folks!

At Fleet we are attempting to replace our own SAML implementation with crewjam/saml.
One of our internal tests failed because of NameID extraction (crewjam/saml will remove any comments from the NameID field).

This PR fixes the issue using the approach Duo recommended for remediation:

If You Maintain a SAML Processing Library

The most obvious remediation here is ensuring your SAML library is extracting the full text of a given XML element when comments are present.

@lucasmrod lucasmrod requested a review from crewjam as a code owner April 17, 2025 18:33
@lucasmrod
Copy link
Author

Hi @crewjam! Let me know if you want me to open an issue to link this PR to.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant