Skip to content

SAML and IdP initiated federation flows #100

@deansaxe

Description

@deansaxe

In #94, the language was changed to require RP initiated federation flows. SAML often uses an IdP initiated federation, e.g. from the Okta dashboard. While this has known security issues (see https://www.identityserver.com/articles/the-dangers-of-saml-idp-initiated-sso), it is also commonly used.

How do we want to handle this moving forward? I see two choices:

  1. Move the requirement for RP initiated flows to SL2, allowing them to continue at SL1 for SAML implementations
  2. Keep the requirement at SL1 and figure out how to device a mechanism for SAML that works similar to https://openid.net/specs/openid-connect-core-1_0.html#ThirdPartyInitiatedLogin

Metadata

Metadata

Assignees

No one assigned

    Labels

    January 2026 InteropExpected to be completed by end of Sept. 2025 for the Jan. 2026 interop.agendasl1sl2

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions