Implement get_last_assertion_issue_instant()#280
Merged
pitbulk merged 2 commits intoSAML-Toolkits:masterfrom Sep 6, 2021
Merged
Implement get_last_assertion_issue_instant()#280pitbulk merged 2 commits intoSAML-Toolkits:masterfrom
pitbulk merged 2 commits intoSAML-Toolkits:masterfrom
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Currently the way of retrieving
IssueInstanttime from the last assertion processedSAMLResponseis possible by (please correct me if there's an easier way):auth.get_last_response_xml()xml_utils.to_etree()xml_utils.query()parse_SAML_to_time()Implementing
get_last_assertion_issue_instant()replaces the four calls above with one.Why retrieve
IssueInstant?There is an odd case where an IdP can send no
notOnOrAfterwithinConditionsorSubjectConfirmationDatain an Assertion, as these parameters are both optional.IssueInstanton the other hand is a required parameter that provides an additional tool for applications to implement additional security measurements by limiting the amount of time they'll process an Assertion pastIssueInstant