SAML is even worse than the article describes, problems like needing to check what the signature actually signs. But I'm optimistic about the future, instead of relying on libraries that do a lot, such as general xml parsing, we can support a subset of SAML and only the dialects of the top ~10 providers. Extreme niche providers can be added ad-hoc and only if the deal size makes it worthwhile.
This one? <a href="https://developers.onelogin.com/docs/saml/" rel="nofollow">https://developers.onelogin.com/docs/saml/
I used to maintain a legacy public IdP with a bespoke saml implementation that predated almost anything and was a nightmare to work with. I always wanted to migrate to one login. Luckily I left that job before embarking in such a nightmarish project.
<a href="https://github.com/SAML-Toolkits/java-saml" rel="nofollow">https://github.com/SAML-Toolkits/java-saml last updated 2+ years ago!
arpinum · · focus · HN ↗
bklyn11201 · · focus · HN ↗
loloquwowndueo · · focus · HN ↗
I used to maintain a legacy public IdP with a bespoke saml implementation that predated almost anything and was a nightmare to work with. I always wanted to migrate to one login. Luckily I left that job before embarking in such a nightmarish project.
bklyn11201 · · focus · HN ↗