Python-saml

Latest version: v2.13.0

Safety actively analyzes 628499 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 5 of 6

2.1.3

Not secure
* Do accesible the ID of the object Logout Request (id attribute)
* Add SAMLServiceProviderBackend reference to the README.md
* Solve HTTPs issue on demos
* Fix PHP-style array element in settings json
* Add fingerprint algorithm support. Previously the toolkit assumed SHA-1 algorithm
* Fix creation of metadata with no SLS, when using settings.get_sp_metadata()
* Allow configuration of metadata caching/expiry via settings
* Allow metadata signing with SP key specified as config value, not file
* Set NAMEID_UNSPECIFIED as default NameIDFormat to prevent conflicts
* Improve validUntil/cacheDuration metadata settings

2.1.2

Not secure
* Fix wrong element order in generated metadata (SLS before NameID). metadata xsd updated
* Added SLO with nameID and SessionIndex in the demos
* Fix Exception message on Destination validation of the Logout_request

2.1.0

Not secure
* Update the dm.xmlsec.binding library to 1.3.2 (Improved transform support, Workaround for buildout problem)
* Fix flask demo settings example.
* Add nameID & sessionIndex support on Logout Request
* Reject SAML Response if not signed and strict = false
* Add ForceAuh and IsPassive support on AuthN Request

2.0.2

Not secure
* Adding AuthnContextClassRef support
* Process nested StatusCode
* Fix settings bug

2.0.1

Not secure
* SSO and SLO (SP-Initiated and IdP-Initiated).
* Assertion and nameId encryption.
* Assertion signature.
* Message signature: AuthNRequest, LogoutRequest, LogoutResponses.
* Enable an Assertion Consumer Service endpoint.
* Enable a Single Logout Service endpoint.
* Publish the SP metadata (which can be signed).

1.1.0

* Security improved, added more checks at the SAMLResponse validation

Page 5 of 6

© 2024 Safety CLI Cybersecurity Inc. All Rights Reserved.