Closed GoogleCodeExporter closed 8 years ago
If the response contains an InResponseTo attribute that links back to an
AuthnRequest, then I agree this is a good idea. If there is no InResponseTo
attribute, then the response is considered to be an unsolicited response.
Original comment by trsc...@gmail.com
on 25 Oct 2011 at 1:39
Implemented in r3189.
Original comment by jaim...@gmail.com
on 15 Oct 2012 at 10:38
Original issue reported on code.google.com by
olavmrk@gmail.com
on 25 Oct 2011 at 1:18