basalt / auth-saml/src / SamlRoutesOptions
Interface: SamlRoutesOptions
Defined in: auth-saml/src/index.ts:686
Properties
bindingCookie?
> optional bindingCookie?: object
Defined in: auth-saml/src/index.ts:702
The HttpOnly cookie binding a login to the browser that started it (see SamlOptions.bindToBrowser). The IdP returns with a cross-site POST, so the cookie is SameSite=None, which browsers only keep with Secure: secure defaults to true unless NODE_ENV is explicitly development or test, and a secure cookie is named __Host-basalt_saml. Browsers treat http://localhost as secure, so secure: true also works there; a non-secure cookie carries no SameSite attribute and relies on the browser's default.
maxAgeSeconds?
> optional maxAgeSeconds?: number
secure?
> optional secure?: boolean
rateLimit?
> optional rateLimit?: false | { limit: number; windowMs: number; }
Defined in: auth-saml/src/index.ts:708
meta.rateLimit on the login and ACS routes (enforced by the http securityPlugin's rate limiter). Default 10 requests per minute per ip and route. false removes it.
successRedirect?
> optional successRedirect?: string
Defined in: auth-saml/src/index.ts:691
When set, the ACS redirects the browser here after login with #access_token=…&refresh_token=…. Omitted → JSON { user, accessToken, refreshToken }.