Skip to content

basalt / auth-saml/src / Saml

Class: Saml ​

Defined in: auth-saml/src/index.ts:509

SAML 2.0 SP-initiated SSO. Signature verification, canonicalization and the SAML protocol are delegated to @node-saml/node-saml; this only wires the result into Auth.socialLogin. A validated assertion is trusted, so the user is logged in with emailVerified: true.

Constructors ​

Constructor ​

> new Saml(auth, providers, options?): Saml

Defined in: auth-saml/src/index.ts:516

Parameters ​

auth ​

Auth

providers ​

SamlProvider[]

options? ​

SamlOptions = {}

Returns ​

Saml

Accessors ​

bindsToBrowser ​

Get Signature ​

> get bindsToBrowser(): boolean

Defined in: auth-saml/src/index.ts:560

Whether consume requires the browser binding (see SamlOptions.bindToBrowser).

Returns ​

boolean

Methods ​

authorize() ​

> authorize(name): Promise<{ binding: string; url: string; }>

Defined in: auth-saml/src/index.ts:569

Starts an SP-initiated login bound to the browser: returns the IdP redirect URL and the binding to keep in an HttpOnly cookie until the ACS POST (pass it back to consume).

Parameters ​

name ​

string

Returns ​

Promise<{ binding: string; url: string; }>


consume() ​

> consume(name, body, options?): Promise<{ created: boolean; tokens: TokenPair; user: PublicUser; }>

Defined in: auth-saml/src/index.ts:589

Validates a posted SAMLResponse and logs the user in by email. With bindsToBrowser on (the default), options.binding must be the one authorize returned to this browser.

Parameters ​

name ​

string

body ​
RelayState? ​

string

SAMLResponse ​

string

options? ​
binding? ​

string

Returns ​

Promise<{ created: boolean; tokens: TokenPair; user: PublicUser; }>


loginUrl() ​

> loginUrl(name, relayState?): Promise<string>

Defined in: auth-saml/src/index.ts:580

The IdP redirect URL with a caller-chosen RelayState. Low level: when bindsToBrowser is on, the response is only accepted if relayState is samlRelayStateFor(binding) for the binding given to consume — prefer authorize.

Parameters ​

name ​

string

relayState? ​

string = ''

Returns ​

Promise<string>


metadata() ​

> metadata(name): string

Defined in: auth-saml/src/index.ts:660

SP metadata XML (hand this to the IdP admin to register the SP).

Parameters ​

name ​

string

Returns ​

string


names() ​

> names(): string[]

Defined in: auth-saml/src/index.ts:548

Returns ​

string[]

Released under the MIT License.