Specifics of your environment
- simpleSAMLphp is an IdP
- SimpleSAMLphp version is 2.5.2
- PHP is version 8.3
- Platform is Linux
- Webserver is an nginx frontend with FPM backend
Describe the bug
If a SAML SP sends an AuthNRequest with the optional parameter AssertionConsumerServiceURL, and that URL is not contained in the SP configured metadata, and the request is not signed, then authentication succeeds and SSP sends the assertion back to one of the URLs from metadata.
However, the SAML spec states
AssertionConsumerServiceURL [Optional]
Specifies by value the location to which the message MUST be returned to the
requester. The responder MUST ensure by some means that the value specified is in fact associated
with the requester.
One way is signed requests - in this case it is okay to continue the authentication and take the received AssertionConsumerServiceURL at face value.
Another way is pre-configured metadata. In that case, a mismatch is a problem.
Expected behavior
In the given situation (unsigned request, stored metadata with different ACS URLs), it is impossible to satisfy both MUST conditions simultaneously; one of the two is always violated. A protocol violation should not lead to successful auth, but raise a fatal protocol error instead.
Specifics of your environment
Describe the bug
If a SAML SP sends an AuthNRequest with the optional parameter AssertionConsumerServiceURL, and that URL is not contained in the SP configured metadata, and the request is not signed, then authentication succeeds and SSP sends the assertion back to one of the URLs from metadata.
However, the SAML spec states
AssertionConsumerServiceURL [Optional]
Specifies by value the location to which the message MUST be returned to the
requester. The responder MUST ensure by some means that the value specified is in fact associated
with the requester.
One way is signed requests - in this case it is okay to continue the authentication and take the received AssertionConsumerServiceURL at face value.
Another way is pre-configured metadata. In that case, a mismatch is a problem.
Expected behavior
In the given situation (unsigned request, stored metadata with different ACS URLs), it is impossible to satisfy both MUST conditions simultaneously; one of the two is always violated. A protocol violation should not lead to successful auth, but raise a fatal protocol error instead.