spring-attic / spring-security-saml

SAML extension for the Spring Security project
Other
419 stars 484 forks source link

CSP issue velocityTemplateId on HTTPPostBinding #522

Open flinden68 opened 2 years ago

flinden68 commented 2 years ago

Content Security Policy does not allow inline javascript. The saml2-post-binding.vm template who is used by default contains inline javascript