Skip to content

basalt / auth-saml/src / assertSamlResponseAlgorithms

Function: assertSamlResponseAlgorithms() ​

> assertSamlResponseAlgorithms(samlResponse, policy): void

Defined in: auth-saml/src/index.ts:325

Refuses a base64 SAMLResponse that uses an XML-DSig algorithm outside policy, or that carries a DOCTYPE / entity declarations. Every SignatureMethod and DigestMethod element — in any namespace or prefix, at any depth (response envelope and assertion signatures alike) — must carry Algorithm attributes that are all in the allowlist. Elements are matched by local name and attributes by local name, as xml-crypto does, so no spelling that the verifier would honour escapes the check. Throws SamlResponseInvalidError.

Parameters ​

samlResponse ​

string

policy ​

SamlAlgorithmPolicy

Returns ​

void

Released under the MIT License.