Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[v13] Validate SAMLIdPServiceProviders ACS endpoints #32220

Merged
merged 1 commit into from Sep 20, 2023

Commits on Sep 20, 2023

  1. Validate SAMLIdPServiceProviders ACS endpoints

    Enforces that all ACS endpoints are HTTPS to prevent any
    XSS attacks. To allow admins to interogate any existing resources
    which may be impacted validation only happens on create and update
    but not get. All usages of SAMLIdPServiceProviders within teleport
    follow all internal retrievals with a call to
    services.ValidateAssertionConsumerServicesEndpoint in order to
    subvert invalid ACS endpoints.
    rosstimothy committed Sep 20, 2023
    Configuration menu
    Copy the full SHA
    8894dd4 View commit details
    Browse the repository at this point in the history