New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Does onelogin.saml2.debug really do anything? #194

dswitzer opened this Issue Oct 5, 2018 · 2 comments


None yet
2 participants

dswitzer commented Oct 5, 2018

Maybe I'm missing something obvious, but I don't see where onelogin.saml2.debug actually does anything within the core code. I thought this was controlling the logging level, but that doesn't appear to be the case.

In tracing the code, it gets mapped to the private Saml2Settings.debug variable, which makes Saml2Settings.isDebugActive() return true or false based on the setting, but I don't see any of the code that actual does anything with this information.

The only place it used is in the acs.jsp to determine how to show errors.

Is that the only thing it's used for?


This comment has been minimized.


pitbulk commented Oct 8, 2018

Is an internal setting of the toolkit.

And the way to use it is with the isDebugActive as you saw on acs.jsp as a way to decide when to show (for debugging) the reason for SAML Messages invalidation.


This comment has been minimized.


dswitzer commented Oct 8, 2018

Thanks for the information.

When I saw the setting in the INI file, it felt like it was controlling the logging output. It might be worth noting in the INI file the debug setting does not affect logging and is simple a boolean to affect your own implementation of the API.

@dswitzer dswitzer closed this Oct 8, 2018

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment