Changes for version 0.03 - 2026-10-03

  • SECURITY: the ACS route never performed the replay check the POD listed. A captured assertion consumer POST (body plus the _saml_flow cookie as sent) could be presented again until flow_ttl expired, and with allow_idp_initiated on, indefinitely.
  • The replay check is now on by default, backed by a `cache` store named by the new `seen` option. The plugin refuses to boot without one; `allow_replay => 1` turns the check off.
  • SECURITY: NotOnOrAfter on the bearer SubjectConfirmationData is now required, as the Web Browser SSO profile says. It was honoured only when present, and IssueInstant is not a freshness check, so an assertion with no window was unbounded in time.
  • The identity carries `replay_until`, the bearer window.
  • INCOMPATIBLE: an application with no `cache` store no longer boots, and an identity provider that omits the bearer NotOnOrAfter is now refused.

Modules

the punk saml subcommands
sign in with SAML 2.0 identity providers
SAML 2.0 service provider for Punk applications
what a refusal throws
one identity provider
SAML metadata, read and written
the AuthnRequest and its binding
a Response, verified
XML-DSig, verified and made
xs:dateTime, both ways