basalt / auth-saml/src / Saml
Class: Saml
Defined in: auth-saml/src/index.ts:509
SAML 2.0 SP-initiated SSO. Signature verification, canonicalization and the SAML protocol are delegated to @node-saml/node-saml; this only wires the result into Auth.socialLogin. A validated assertion is trusted, so the user is logged in with emailVerified: true.
Constructors
Constructor
> new Saml(auth, providers, options?): Saml
Defined in: auth-saml/src/index.ts:516
Parameters
auth
providers
options?
SamlOptions = {}
Returns
Saml
Accessors
bindsToBrowser
Get Signature
> get bindsToBrowser(): boolean
Defined in: auth-saml/src/index.ts:560
Whether consume requires the browser binding (see SamlOptions.bindToBrowser).
Returns
boolean
Methods
authorize()
> authorize(name): Promise<{ binding: string; url: string; }>
Defined in: auth-saml/src/index.ts:569
Starts an SP-initiated login bound to the browser: returns the IdP redirect URL and the binding to keep in an HttpOnly cookie until the ACS POST (pass it back to consume).
Parameters
name
string
Returns
Promise<{ binding: string; url: string; }>
consume()
> consume(name, body, options?): Promise<{ created: boolean; tokens: TokenPair; user: PublicUser; }>
Defined in: auth-saml/src/index.ts:589
Validates a posted SAMLResponse and logs the user in by email. With bindsToBrowser on (the default), options.binding must be the one authorize returned to this browser.
Parameters
name
string
body
RelayState?
string
SAMLResponse
string
options?
binding?
string
Returns
Promise<{ created: boolean; tokens: TokenPair; user: PublicUser; }>
loginUrl()
> loginUrl(name, relayState?): Promise<string>
Defined in: auth-saml/src/index.ts:580
The IdP redirect URL with a caller-chosen RelayState. Low level: when bindsToBrowser is on, the response is only accepted if relayState is samlRelayStateFor(binding) for the binding given to consume — prefer authorize.
Parameters
name
string
relayState?
string = ''
Returns
Promise<string>
metadata()
> metadata(name): string
Defined in: auth-saml/src/index.ts:660
SP metadata XML (hand this to the IdP admin to register the SP).
Parameters
name
string
Returns
string
names()
> names(): string[]
Defined in: auth-saml/src/index.ts:548
Returns
string[]