basalt / auth-saml/src / SamlOptions
Interface: SamlOptions
Defined in: auth-saml/src/index.ts:111
Extended by
Properties
assertionReplayCache?
> optional assertionReplayCache?: SamlAssertionReplayCache
Defined in: auth-saml/src/index.ts:141
Single-use store for consumed assertion ids. Default: an in-process map (entries expire with the assertion). Pass a shared one (Redis SET NX PX, a unique DB row…) on multi-replica deployments that opt in to IdP-initiated SSO.
bindToBrowser?
> optional bindToBrowser?: boolean
Defined in: auth-saml/src/index.ts:153
Bind every SP-initiated login to the browser that started it (login-CSRF protection). Default true: Saml.authorize returns a random binding to keep in an HttpOnly cookie (samlRoutes does) and sends its hash as the RelayState; Saml.consume refuses a response whose RelayState does not match the binding presented with it — so a SAMLResponse the attacker obtained for their own account cannot be posted from a victim's browser. Enforced with validateInResponseTo: 'always' (the default); IdP-initiated SSO ('ifPresent' / 'never') cannot be bound to a browser and is login-CSRF-able by nature. false opts out.
cacheProvider?
> optional cacheProvider?: SamlCacheProvider
Defined in: auth-saml/src/index.ts:135
Shared store for outstanding AuthnRequest ids — required on multi-replica deployments.
createClient?
> optional createClient?: (provider) => SamlClient
Defined in: auth-saml/src/index.ts:117
Factory for the underlying SAML client. Default: @node-saml/node-saml. Injectable for tests so the crypto path is exercised by the real library in production but stubbed in unit tests.
Parameters
provider
Returns
host?
> optional host?: string
Defined in: auth-saml/src/index.ts:119
Host used when building the AuthnRequest (optional).
validateInResponseTo?
> optional validateInResponseTo?: ValidateInResponseToMode
Defined in: auth-saml/src/index.ts:133
Assertion-replay protection. Default 'always': every response must carry an InResponseTo matching an AuthnRequest this SP issued and not yet consumed, so unsolicited (IdP-initiated) responses are refused. Set 'ifPresent' to opt in to IdP-initiated SSO (or 'never'); consumed assertion ids are then also kept in assertionReplayCache so a captured response cannot be re-posted.
The request ids live in cacheProvider — node-saml's in-process cache by default. Across several replicas without sticky sessions, a login started on one replica and returning to another will fail with AUTH_SAML_RESPONSE_INVALID; pass a shared cacheProvider (Redis, your database…), or set 'never' to opt out and accept the replay window.