Repository navigation
Conversation
The samltest.id domain is compromised. Point the README, package docs, and the trivial example at samltest.dev instead. The signed ArtifactResponse test fixtures (and the IdP metadata they are validated against) keep samltest.id: they are an offline capture whose signature would be invalidated by editing, and they are never fetched over the network.
c9s
force-pushed
the
replace-samltest-id
branch
from
September 10, 2026 07:14
467f433 to
d31a136
Compare
samltest.dev now creates a separate IdP for each app instead of one shared IdP: - IdP metadata lives at https://www.samltest.dev/apps/<APP_ID>/metadata (the old /saml/idp path redirects to the homepage) - SPs are registered by setting spAcsUrl/spEntityId on the app, via the web UI or PUT /api/apps/:id, instead of uploading a metadata file - the login page asks which test user to log in as, with no password Update the README and the matching saml.go package doc, and make example/trivial take the IdP metadata URL as an -idp-metadata-url flag. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CKdGrFnSkdNtKRHVkNXT7y
c9s
force-pushed
the
replace-samltest-id
branch
from
September 10, 2026 08:12
2355834 to
37fadf6
Compare
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
The
samltest.iddomain is compromised. This PR points user-facing references atsamltest.devinstead, so nobody following the docs or running the example talks to the compromised host.Updated:
README.md: IdP metadata URL, SP metadata upload page, SSO redirect URL, and mentions in the walkthroughsaml.go: the same content in the package doc commentexample/trivial/trivial.go:idpMetadataURLnow useshttps://samltest.dev/saml/idp(the only code that actually made a network request to the site)Intentionally unchanged
The test fixtures in
testdata/still referencesamltest.id:TestParseXMLArtifactResponse_responseis a real signed ArtifactResponse captured from the IdP in 2021. Editing the issuer invalidates the XML signature, soTestParseXMLArtifactResponse/TestParseBadXMLArtifactResponsefail.TestParseXMLArtifactResponse_assertionis the expected parse result of that response.TestGetArtifactBindingLocation_IDPMetadatamust keep itsentityIDmatching the response issuer, and the assertion inTestGetArtifactBindingLocationmatches that file.These fixtures are only read locally and never fetched. The test comments now say the response is a signed capture from the former
samltest.idIdP.Testing
go test -count=1 ./...passesgo vet ./...is clean🤖 Generated with Claude Code
https://claude.ai/code/session_01CKdGrFnSkdNtKRHVkNXT7y