Skip to content

basalt / auth-saml/src / ValidateInResponseToMode

Type Alias: ValidateInResponseToMode ​

> ValidateInResponseToMode = "never" | "ifPresent" | "always"

Defined in: auth-saml/src/index.ts:187

Replay protection: bind each SAMLResponse to an AuthnRequest this SP issued. always (the default here — node-saml's own default is never) rejects a response whose InResponseTo is missing, unknown or already consumed, closing the window in which a captured assertion can be replayed until its NotOnOrAfter. ifPresent additionally accepts unsolicited (IdP-initiated) responses — an explicit opt-in.

Released under the MIT License.