Skip to content

REF-27: Remove validation of the specVersion attribute value in assertions - #94

Merged
thomasnymand merged 1 commit into
masterfrom
feature/REF-27-remove-specversion-value-validation
Aug 26, 2026
Merged

thomasnymand merged 1 commit into
masterfrom
feature/REF-27-remove-specversion-value-validation

Conversation

@thomasnymand

Copy link
Copy Markdown
Collaborator

validateAttributeStatement required the specVersion attribute to equal "OIO-SAML-3.0".

OIOSAML 4.0.0 changes that value to https://data.gov.dk/saml/profile/oio/4.0.0/, so an assertion issued under the newer profile was rejected, and every future profile revision would need a new release of this library. The value announces which profile version the assertion was issued under, and nothing in the profiles asks the SP to check it.

Changes

  • Only the presence of specVersion is required now, as mandated by [OIO-AP-01] (the attribute is Mandatory in every attribute profile in both 3.0.3 and 4.0.0). The value is logged at debug level.
  • Constants.SPEC_VER_VAL removed as unused. It is a compile-time constant, so existing binaries are unaffected, but recompiling against it will fail — worth a line in RELEASE_NOTES.md at release time.
  • IdpUtil gained overloads taking a specVersion (existing signatures delegate with the 3.0 value; null omits the attribute), so the 23 existing call sites are untouched.

Verification

mvn -pl oiosaml test → 114 tests, 1 failure: the pre-existing OIOBPPUtilTest (JDK 26 JAXB incompatibility), which also fails on master.

New tests cover an assertion carrying the 4.0.0 value and an assertion missing the attribute. With the production change reverted, the 4.0.0 test fails with specVersion Was: https://data.gov.dk/saml/profile/oio/4.0.0/ Expected: OIO-SAML-3.0.

…tions

validateAttributeStatement required specVersion to equal "OIO-SAML-3.0". The
OIOSAML 4.0.0 profile changes that value to
https://data.gov.dk/saml/profile/oio/4.0.0/, so assertions issued under the
newer profile were rejected, and every future profile revision would need a new
release. The value announces which profile version the assertion was issued
under, and nothing in the profiles asks the SP to check it.

Only the presence of the attribute is required now, as mandated by [OIO-AP-01]
in both 3.0.3 and 4.0.0. Constants.SPEC_VER_VAL is removed as unused; it is a
compile time constant, so existing binaries are unaffected, but recompiling
against it will fail.

Tests cover an assertion carrying the 4.0.0 value and one missing the attribute.
@thomasnymand
thomasnymand requested a review from mthiim August 13, 2026 19:37
@thomasnymand
thomasnymand merged commit b00d2f4 into master Aug 26, 2026
2 checks passed
@thomasnymand
thomasnymand deleted the feature/REF-27-remove-specversion-value-validation branch August 26, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants