All work
- Consent condition on back-channel flows invoked incorrectlyIDP-2358Resolved issue: IDP-2358Scott Cantor
- SOAP client wiring references old bean IDIDP-2352Resolved issue: IDP-2352Scott Cantor
- Error unmarshalling message from input stream: Saw invalid child elementIDP-2344Resolved issue: IDP-2344Scott Cantor
- Duplicative handler checking message issuer in SAML proxy flowIDP-2318Resolved issue: IDP-2318Scott Cantor
- SAML Auth servlet not covered by response filterIDP-2299Resolved issue: IDP-2299Scott Cantor
- Missing async logout error mapping for SessionNotFoundIDP-2257Resolved issue: IDP-2257Scott Cantor
- Warn when defaultAuthenticationMethods used without disallowedFeaturesIDP-2255Resolved issue: IDP-2255Scott Cantor
- Map OIDC ACRs to SAML AC classes in proxied authenticationIDP-2251Resolved issue: IDP-2251Scott Cantor
- Option to randomize FriendlyNameIDP-2216Resolved issue: IDP-2216Scott Cantor
- Deprecation warning is incorrect in profile configIDP-2208Resolved issue: IDP-2208Scott Cantor
- Implement new SAML profile settingsIDP-2076Resolved issue: IDP-2076Scott Cantor
- Refactor assertion-specific profile config settingsIDP-2067Resolved issue: IDP-2067Scott Cantor
- Set RequesterID when proxying authn requestsIDP-2031Resolved issue: IDP-2031Scott Cantor
- Allow for NameID within AuthnRequests while proxyingIDP-2003Resolved issue: IDP-2003Scott Cantor
- Blocking unsigned requests via profile configurationIDP-1974Resolved issue: IDP-1974Scott Cantor
- Some IdP tests run with destroyed beans (because of Context lifetimes)IDP-1967Resolved issue: IDP-1967Rod Widdowson
- Remove ID-WSF SAML delegation supportIDP-1958Resolved issue: IDP-1958Scott Cantor
- Multiple IdPAttributes mapped to one encoded name don't get combined.IDP-1936Resolved issue: IDP-1936Scott Cantor
- Allow override of HttpClient used by SOAP clientIDP-1918Resolved issue: IDP-1918Scott Cantor
- Add option to disable outbound logoutIDP-1829Resolved issue: IDP-1829Scott Cantor
- Construction of Scoping in AuthnRequests is brokenIDP-1803Resolved issue: IDP-1803Scott Cantor
- AuthenticatingAuthority elements created in the wrong orderIDP-1759Resolved issue: IDP-1759Scott Cantor
- Allow suppression of AuthenticatingAuthority elementsIDP-1758Resolved issue: IDP-1758Scott Cantor
- Configurable shibboleth.OutgoingSOAPBindingsIDP-1740Resolved issue: IDP-1740Scott Cantor
- Add support for mapping proxied Attribute into issued AuthnContextIDP-1728Resolved issue: IDP-1728Scott Cantor
- Auditing failed AuthnRequests with Subject log the wrong usernameIDP-1701Resolved issue: IDP-1701Scott Cantor
- Include ProtocolBinding in proxied SAML AuthnRequestIDP-1653Resolved issue: IDP-1653Scott Cantor
- Success status with unexpected status message during logoutIDP-1600Resolved issue: IDP-1600Scott Cantor
- Provisionally deprecate SAML delegation flowIDP-1578Resolved issue: IDP-1578Scott Cantor
- SOAP fault generation in ECP flow is brokenIDP-1574Resolved issue: IDP-1574Scott Cantor
- SAML login flow not extracting request ID for InResponseTo checkIDP-1572Resolved issue: IDP-1572Brent Putman
- Add lookup strategy for populating Address attributesIDP-1477Resolved issue: IDP-1477Scott Cantor
- Freshen idwsfconsumer libraryIDP-1471Resolved issue: IDP-1471Tom Zeller
- SAML 2 Response Destination not properly URI encodedIDP-1468Resolved issue: IDP-1468Scott Cantor
- Provide way to set forceAuthn on an RP from the IdP sideIDP-1318Resolved issue: IDP-1318Scott Cantor
- Logout flow resolving encryption keys too aggressivelyIDP-1302Resolved issue: IDP-1302Scott Cantor
- Missing NameQualifier and SPNameQualifier in LogoutRequest result in UnknownPrincipalIDP-1297Resolved issue: IDP-1297Scott Cantor
- Non-standard extension to discriminate logout endpointsIDP-1296Resolved issue: IDP-1296Scott Cantor
- Log output on failure to find encryption key should be clearer.IDP-1254Resolved issue: IDP-1254Scott Cantor
- Support for RequestedAttributes AuthnRequest extensionIDP-1217Resolved issue: IDP-1217Scott Cantor
- Encoders should complain on less than sensible inputIDP-1165Resolved issue: IDP-1165Rod Widdowson
- Support for AuthenticatingAuthorityIDP-1117Resolved issue: IDP-1117Scott Cantor
- Intermittent Assertion signature with IdP-initiated SSOIDP-1108Resolved issue: IDP-1108Scott Cantor
- Need a unit test in idp-conf for the ECP flowIDP-1069Tom Zeller
- Delegation Liberty SSOS flow completely broken on Subject C14NIDP-1068Resolved issue: IDP-1068Brent Putman
- Async LogoutRequest fails with EncryptedIDIDP-1067Resolved issue: IDP-1067Scott Cantor
- Profile setting to disallow RequestedAuthnContext in requestsIDP-1049Resolved issue: IDP-1049Scott Cantor
- ClientStorageService error when issuing delegated assertionIDP-1022Resolved issue: IDP-1022Brent Putman
- Delegation Liberty SSOS flow Assertion Subject C14N fails for transient NameIDsIDP-1012Resolved issue: IDP-1012Brent Putman
- SOAP logout flow mislabeled as abstractIDP-984Resolved issue: IDP-984Scott Cantor
50 of 122
Consent condition on back-channel flows invoked incorrectly
Fixed
Basics
Logistics
Basics
Logistics
Description
Environment
None
Created February 12, 2025 at 7:58 PM
Updated March 27, 2025 at 2:23 PM
Resolved February 12, 2025 at 8:00 PM
The consent check condition used on the query and CAS validate flows is being called with the legacy apply() syntax in a flow expression instead of test().
It’s working because this is normally not messed with and is either set to TRUE or FALSE using our Guava-backed beans that still implement the old interface.