REF-27: Remove validation of the specVersion attribute value in assertions - #94
Merged
thomasnymand merged 1 commit intoAug 26, 2026
Conversation
…tions validateAttributeStatement required specVersion to equal "OIO-SAML-3.0". The OIOSAML 4.0.0 profile changes that value to https://data.gov.dk/saml/profile/oio/4.0.0/, so assertions issued under the newer profile were rejected, and every future profile revision would need a new release. The value announces which profile version the assertion was issued under, and nothing in the profiles asks the SP to check it. Only the presence of the attribute is required now, as mandated by [OIO-AP-01] in both 3.0.3 and 4.0.0. Constants.SPEC_VER_VAL is removed as unused; it is a compile time constant, so existing binaries are unaffected, but recompiling against it will fail. Tests cover an assertion carrying the 4.0.0 value and one missing the attribute.
mthiim
approved these changes
Aug 26, 2026
thomasnymand
deleted the
feature/REF-27-remove-specversion-value-validation
branch
August 26, 2026 15:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
validateAttributeStatementrequired thespecVersionattribute to equal"OIO-SAML-3.0".OIOSAML 4.0.0 changes that value to
https://data.gov.dk/saml/profile/oio/4.0.0/, so an assertion issued under the newer profile was rejected, and every future profile revision would need a new release of this library. The value announces which profile version the assertion was issued under, and nothing in the profiles asks the SP to check it.Changes
specVersionis required now, as mandated by[OIO-AP-01](the attribute is Mandatory in every attribute profile in both 3.0.3 and 4.0.0). The value is logged at debug level.Constants.SPEC_VER_VALremoved as unused. It is a compile-time constant, so existing binaries are unaffected, but recompiling against it will fail — worth a line inRELEASE_NOTES.mdat release time.IdpUtilgained overloads taking aspecVersion(existing signatures delegate with the 3.0 value;nullomits the attribute), so the 23 existing call sites are untouched.Verification
mvn -pl oiosaml test→ 114 tests, 1 failure: the pre-existingOIOBPPUtilTest(JDK 26 JAXB incompatibility), which also fails onmaster.New tests cover an assertion carrying the 4.0.0 value and an assertion missing the attribute. With the production change reverted, the 4.0.0 test fails with
specVersion Was: https://data.gov.dk/saml/profile/oio/4.0.0/ Expected: OIO-SAML-3.0.