italia / spid-sp-shibboleth

Middleware SPID basato su Shibboleth
Creative Commons Zero v1.0 Universal
13 stars 5 forks source link

Add security policy for blocking unsolicited responses #15

Closed robertogallea closed 3 years ago

robertogallea commented 3 years ago

This PR allows passing SPID compliance tests 16, 17 and 18 by blocking uncorrelated responses with unspecified, missing or wrong inResponseTo response attribute

Requires Shibboleth SP v3.1+ to work