Skip to content

basalt / auth-saml/src / SamlProvider

Interface: SamlProvider ​

Defined in: auth-saml/src/index.ts:48

Properties ​

acceptedClockSkewMs? ​

> optional acceptedClockSkewMs?: number

Defined in: auth-saml/src/index.ts:74

Clock skew tolerated on NotBefore / NotOnOrAfter, ms. Default 0 (node-saml's default); at most 5 minutes.


allowAnyEmailDomain? ​

> optional allowAnyEmailDomain?: true

Defined in: auth-saml/src/index.ts:90

Explicit opt-out of allowedEmailDomains when several providers are configured: this IdP may assert any email. Only for an IdP you fully control.


allowedEmailDomains? ​

> optional allowedEmailDomains?: string[]

Defined in: auth-saml/src/index.ts:85

Email domains this IdP is trusted to assert (exact, case-insensitive match on the part after @; list subdomains explicitly). An assertion for any other domain is rejected with AUTH_SAML_RESPONSE_INVALID.

In B2B SaaS each customer's IdP admin controls what their IdP signs, so without this list one customer's IdP could log in as another customer's users. It is required when more than one provider is configured, unless the provider explicitly sets allowAnyEmailDomain.


allowSha1? ​

> optional allowSha1?: true

Defined in: auth-saml/src/index.ts:108

Legacy opt-in: also accept SHA-1 (rsa-sha1 signatures, sha1 digests) on top of the default algorithm lists. SHA-1 is collision-broken; enable it only for an IdP that cannot sign with SHA-256, and plan to turn it off.


callbackUrl ​

> callbackUrl: string

Defined in: auth-saml/src/index.ts:57

ACS URL the IdP POSTs the SAMLResponse to.


digestAlgorithms? ​

> optional digestAlgorithms?: string[]

Defined in: auth-saml/src/index.ts:102

XML-DSig DigestMethod/@Algorithm URIs accepted. Replaces the default DEFAULT_SAML_DIGEST_ALGORITHMS (SHA-256/384/512).


emailAttribute? ​

> optional emailAttribute?: string

Defined in: auth-saml/src/index.ts:63

Attribute to read the email from. When set, ONLY this attribute is read (an assertion without it is refused — no silent fallback to another claim or the NameID). Default: email / common email claims / an email-shaped NameID.


entryPoint ​

> entryPoint: string

Defined in: auth-saml/src/index.ts:51

IdP Single-Sign-On URL (HTTP-Redirect binding).


idpCert ​

> idpCert: string | string[]

Defined in: auth-saml/src/index.ts:53

IdP signing certificate(s) (PEM). Used to verify the assertion signature.


issuer ​

> issuer: string

Defined in: auth-saml/src/index.ts:55

SP entity id (this app's issuer).


name ​

> name: string

Defined in: auth-saml/src/index.ts:49


signatureAlgorithms? ​

> optional signatureAlgorithms?: string[]

Defined in: auth-saml/src/index.ts:97

XML-DSig SignatureMethod/@Algorithm URIs accepted on the response and the assertion. Replaces the default DEFAULT_SAML_SIGNATURE_ALGORITHMS (RSA-SHA256/384/512, ECDSA-SHA256/384/512). Every SignatureMethod in the response must be listed, otherwise it is refused with AUTH_SAML_RESPONSE_INVALID.


wantAuthnResponseSigned? ​

> optional wantAuthnResponseSigned?: boolean

Defined in: auth-saml/src/index.ts:69

Require the whole <Response> to be signed, on top of the assertion (which is always required to be signed). Default true. Some IdPs (AD FS, Entra ID by default) sign only the assertion — set false for those.

Released under the MIT License.