Skip to content

Provide templating or extension to generate SAML2 POST form #9529

Open
@tkupka

Description

@tkupka

The Saml2WebSsoAuthenticationRequestFilter#createSamlPostRequestFormData(...) should allow to customize generated HTML form for SAML2 login request.

The Saml2WebSsoAuthenticationRequestFilter#createSamlPostRequestFormData(...) create a HTML form which is hardcoded. It should supports custom form generation by adding a templating or providing extension for custom implementation.
The existing implementation uses <body onload=\"document.forms[0].submit()\"> which is preventing for adopting stricter CSP see https://csp.withgoogle.com/docs/adopting-csp.html. The onLoad event handler must be added from extrenal js file.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions