basalt / auth-saml/src / ValidateInResponseToMode
Type Alias: ValidateInResponseToMode
> ValidateInResponseToMode = "never" | "ifPresent" | "always"
Defined in: auth-saml/src/index.ts:187
Replay protection: bind each SAMLResponse to an AuthnRequest this SP issued. always (the default here — node-saml's own default is never) rejects a response whose InResponseTo is missing, unknown or already consumed, closing the window in which a captured assertion can be replayed until its NotOnOrAfter. ifPresent additionally accepts unsolicited (IdP-initiated) responses — an explicit opt-in.