Skip to content

Commit

Permalink
patching 1.8.0-pl1 into 1.12.1
Browse files Browse the repository at this point in the history
  • Loading branch information
ntli239 committed Apr 23, 2022
1 parent c38d724 commit 023ce2f
Show file tree
Hide file tree
Showing 2 changed files with 3 additions and 1 deletion.
2 changes: 1 addition & 1 deletion lib/onelogin/ruby-saml/response.rb
Original file line number Diff line number Diff line change
Expand Up @@ -614,7 +614,7 @@ def validate_in_response_to
def validate_audience
return true if options[:skip_audience]
return true if settings.sp_entity_id.nil? || settings.sp_entity_id.empty?

return true if settings.issuer_audience.empty? == false && audiences.include?(settings.issuer_audience)
if audiences.empty?
return true unless settings.security[:strict_audience_validation]
return append_error("Invalid Audiences. The <AudienceRestriction> element contained only empty <Audience> elements. Expected audience #{settings.sp_entity_id}.")
Expand Down
2 changes: 2 additions & 0 deletions lib/onelogin/ruby-saml/settings.rb
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,9 @@ def initialize(overrides = {}, keep_security_attributes = false)
attr_accessor :idp_attribute_names
attr_accessor :idp_name_qualifier
attr_accessor :valid_until

# SP Data
attr_accessor :issuer_audience
attr_writer :sp_entity_id
attr_accessor :assertion_consumer_service_url
attr_reader :assertion_consumer_service_binding
Expand Down

0 comments on commit 023ce2f

Please sign in to comment.