basalt / auth-saml/src / assertSamlResponseAlgorithms
Function: assertSamlResponseAlgorithms()
> assertSamlResponseAlgorithms(samlResponse, policy): void
Defined in: auth-saml/src/index.ts:325
Refuses a base64 SAMLResponse that uses an XML-DSig algorithm outside policy, or that carries a DOCTYPE / entity declarations. Every SignatureMethod and DigestMethod element — in any namespace or prefix, at any depth (response envelope and assertion signatures alike) — must carry Algorithm attributes that are all in the allowlist. Elements are matched by local name and attributes by local name, as xml-crypto does, so no spelling that the verifier would honour escapes the check. Throws SamlResponseInvalidError.
Parameters
samlResponse
string
policy
Returns
void