Skip to content

Replace compromised samltest.id domain with samltest.dev - #668

Open
c9s wants to merge 2 commits into
crewjam:mainfrom
c9s:replace-samltest-id
Open

c9s wants to merge 2 commits into
crewjam:mainfrom
c9s:replace-samltest-id

Conversation

@c9s

@c9s c9s commented Sep 10, 2026

Copy link
Copy Markdown

Summary

The samltest.id domain is compromised. This PR points user-facing references at samltest.dev instead, so nobody following the docs or running the example talks to the compromised host.

Updated:

  • README.md: IdP metadata URL, SP metadata upload page, SSO redirect URL, and mentions in the walkthrough
  • saml.go: the same content in the package doc comment
  • example/trivial/trivial.go: idpMetadataURL now uses https://samltest.dev/saml/idp (the only code that actually made a network request to the site)

Intentionally unchanged

The test fixtures in testdata/ still reference samltest.id:

  • TestParseXMLArtifactResponse_response is a real signed ArtifactResponse captured from the IdP in 2021. Editing the issuer invalidates the XML signature, so TestParseXMLArtifactResponse / TestParseBadXMLArtifactResponse fail.
  • TestParseXMLArtifactResponse_assertion is the expected parse result of that response.
  • TestGetArtifactBindingLocation_IDPMetadata must keep its entityID matching the response issuer, and the assertion in TestGetArtifactBindingLocation matches that file.

These fixtures are only read locally and never fetched. The test comments now say the response is a signed capture from the former samltest.id IdP.

Testing

  • go test -count=1 ./... passes
  • go vet ./... is clean

🤖 Generated with Claude Code

https://claude.ai/code/session_01CKdGrFnSkdNtKRHVkNXT7y

@c9s
c9s requested a review from crewjam as a code owner September 10, 2026 07:11
The samltest.id domain is compromised. Point the README, package docs,
and the trivial example at samltest.dev instead.

The signed ArtifactResponse test fixtures (and the IdP metadata they
are validated against) keep samltest.id: they are an offline capture
whose signature would be invalidated by editing, and they are never
fetched over the network.
@c9s
c9s force-pushed the replace-samltest-id branch from 467f433 to d31a136 Compare September 10, 2026 07:14
samltest.dev now creates a separate IdP for each app instead of one
shared IdP:

- IdP metadata lives at https://www.samltest.dev/apps/<APP_ID>/metadata
  (the old /saml/idp path redirects to the homepage)
- SPs are registered by setting spAcsUrl/spEntityId on the app, via the
  web UI or PUT /api/apps/:id, instead of uploading a metadata file
- the login page asks which test user to log in as, with no password

Update the README and the matching saml.go package doc, and make
example/trivial take the IdP metadata URL as an -idp-metadata-url flag.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CKdGrFnSkdNtKRHVkNXT7y
@c9s
c9s force-pushed the replace-samltest-id branch from 2355834 to 37fadf6 Compare September 10, 2026 08:12
@c9s

c9s commented Sep 19, 2026

Copy link
Copy Markdown
Author

These go lint issues are not my calls:
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant