Skip to content

Add note about using AssertionConsumerServiceURL - #1834

Merged
nick-gagliardi merged 1 commit into
auth0:mainfrom
adamjmcgrath:patch-2
Sep 4, 2026
Merged

Add note about using AssertionConsumerServiceURL#1834
nick-gagliardi merged 1 commit into
auth0:mainfrom
adamjmcgrath:patch-2

Conversation

@adamjmcgrath

Copy link
Copy Markdown
Contributor

Description

Auth0 does not substitute the AssertionConsumerServiceURL template variable if the AuthnRequest is not signed, because the AssertionConsumerServiceURL should not be trusted when the AuthnRequest is not signed.

Checklist

  • I've read and followed CONTRIBUTING.md.
  • I've tested the site build for this change locally.
  • I've made appropriate docs updates for any code or config changes.
  • I've coordinated with the Product Docs and/or Docs Management team about non-trivial changes.

@adamjmcgrath
adamjmcgrath requested a review from a team as a code owner September 4, 2026 09:17
@nick-gagliardi
nick-gagliardi merged commit 1f0d1eb into auth0:main Sep 4, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants