basalt / auth-saml/src / SamlProvider
Interface: SamlProvider
Defined in: auth-saml/src/index.ts:48
Properties
acceptedClockSkewMs?
> optional acceptedClockSkewMs?: number
Defined in: auth-saml/src/index.ts:74
Clock skew tolerated on NotBefore / NotOnOrAfter, ms. Default 0 (node-saml's default); at most 5 minutes.
allowAnyEmailDomain?
> optional allowAnyEmailDomain?: true
Defined in: auth-saml/src/index.ts:90
Explicit opt-out of allowedEmailDomains when several providers are configured: this IdP may assert any email. Only for an IdP you fully control.
allowedEmailDomains?
> optional allowedEmailDomains?: string[]
Defined in: auth-saml/src/index.ts:85
Email domains this IdP is trusted to assert (exact, case-insensitive match on the part after @; list subdomains explicitly). An assertion for any other domain is rejected with AUTH_SAML_RESPONSE_INVALID.
In B2B SaaS each customer's IdP admin controls what their IdP signs, so without this list one customer's IdP could log in as another customer's users. It is required when more than one provider is configured, unless the provider explicitly sets allowAnyEmailDomain.
allowSha1?
> optional allowSha1?: true
Defined in: auth-saml/src/index.ts:108
Legacy opt-in: also accept SHA-1 (rsa-sha1 signatures, sha1 digests) on top of the default algorithm lists. SHA-1 is collision-broken; enable it only for an IdP that cannot sign with SHA-256, and plan to turn it off.
callbackUrl
> callbackUrl: string
Defined in: auth-saml/src/index.ts:57
ACS URL the IdP POSTs the SAMLResponse to.
digestAlgorithms?
> optional digestAlgorithms?: string[]
Defined in: auth-saml/src/index.ts:102
XML-DSig DigestMethod/@Algorithm URIs accepted. Replaces the default DEFAULT_SAML_DIGEST_ALGORITHMS (SHA-256/384/512).
emailAttribute?
> optional emailAttribute?: string
Defined in: auth-saml/src/index.ts:63
Attribute to read the email from. When set, ONLY this attribute is read (an assertion without it is refused — no silent fallback to another claim or the NameID). Default: email / common email claims / an email-shaped NameID.
entryPoint
> entryPoint: string
Defined in: auth-saml/src/index.ts:51
IdP Single-Sign-On URL (HTTP-Redirect binding).
idpCert
> idpCert: string | string[]
Defined in: auth-saml/src/index.ts:53
IdP signing certificate(s) (PEM). Used to verify the assertion signature.
issuer
> issuer: string
Defined in: auth-saml/src/index.ts:55
SP entity id (this app's issuer).
name
> name: string
Defined in: auth-saml/src/index.ts:49
signatureAlgorithms?
> optional signatureAlgorithms?: string[]
Defined in: auth-saml/src/index.ts:97
XML-DSig SignatureMethod/@Algorithm URIs accepted on the response and the assertion. Replaces the default DEFAULT_SAML_SIGNATURE_ALGORITHMS (RSA-SHA256/384/512, ECDSA-SHA256/384/512). Every SignatureMethod in the response must be listed, otherwise it is refused with AUTH_SAML_RESPONSE_INVALID.
wantAuthnResponseSigned?
> optional wantAuthnResponseSigned?: boolean
Defined in: auth-saml/src/index.ts:69
Require the whole <Response> to be signed, on top of the assertion (which is always required to be signed). Default true. Some IdPs (AD FS, Entra ID by default) sign only the assertion — set false for those.