DMKEBUSINESSGMBH / mksamlauth

SSO Authentication for your TYPO3 Frontend
https://www.dmk-ebusiness.de
GNU General Public License v2.0
3 stars 7 forks source link

Activate signing and encryption for auth request. #214

Closed schneiel closed 2 years ago

schneiel commented 2 years ago

This is a security issue. The title says it all.

The variable $trustOptions should be prospectively outscored from the PartyContainer. It should be configurable. But because the fix has to be done quickly, here is a quick and dirty one.