Comments (5)
The console doesn't send the URL to the backend.
It's reproducible with https://mocksaml.com/api/saml/metadata on save and update.
I'll fix it.
from zitadel.
CC @stebenz
Relates to https://discord.com/channels/927474939156643850/1019895518383583323/threads/1206913003312775188
from zitadel.
@HungryHowies Just to differentiate, the expected behaviour still exists but the error you are getting is in reading the Bookstack metadata.xml.
Could you please provide an example metadata.xml from your bookstack instance? So that we can try to sort out what the problem with this file format is? Did you also try to upload the file directly not only through the URL?
from zitadel.
Hey @stebenz
Thx for the reply
@HungryHowies Just to differentiate, the expected behaviour still exists but the error you are getting is in reading the Bookstack metadata.xml.
This is my XML.
NOTE: domain.com is my place holder.
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" validUntil="2024-02-21T22:03:53Z"
cacheDuration="PT604800S" entityID="https://bookstack.domain.com/saml2/metadata">
<md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false"
protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
Location="https://bookstack.domain.com/saml2/sls"/>
<md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="https://bookstack.domain.com/saml2/acs" index="1"/>
</md:SPSSODescriptor>
</md:EntityDescriptor>
Did you also try to upload the file directly not only through the URL?
Yes that works great using the XML file upload and using Option 3: "Create a minimal metadata file on the fly providing ENTITYID and ACS URL".
Also note that Zitadel Version 2.37.3 works great using the URL.
EDIT: Only reason I bring this up is some customers dont have an option of uploading XMl files.
from zitadel.
@stebenz i guess that the parsing might fail because of a missing header / content type mismatch when retrieving the metadata endpoint.
from zitadel.
Related Issues (20)
- Scope for requesting only authorizations of specific organization(s)
- The verify button in email should NOT be present HOT 1
- [Bug]: Multiple Setup/Init Issues
- Support for IdP Initiated SAML SSO to OIDC application HOT 1
- validate adding ordering columns to events2 indexes
- [Bug]: There isn't any migration associated with the new table of privacy_policies4.
- Improve Benchmarking HOT 2
- [Bug]: Can't login via ZITADEL using oauth2-proxy when enabling proxy-protocol. Runs in kubernetes with ingress-nginx HOT 1
- Search: Add issues & discussions to Algolia search
- OIDC signing key resource API
- OIDC signing key usage
- [Bug]: Custom Login UI - failed when process in idps/callback HOT 2
- OIDC signing key management from console HOT 1
- Password reuse prevention policy HOT 1
- [Bug]: saml provider failed to parse certificate: x509: malformed certificate
- Extend configuration for SMTP providers HOT 2
- Remove Password Age Policy HOT 5
- [Bug]: Filters on userlist are ignored
- [Bug]: Automatic update setting in Microsoft provider causing issues with guest users
- Guide(integrate): Login to Proxmox
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from zitadel.