Skip to content

Commit 84c1730

Browse files
committed
Enable the security validation mode while processing signatures. This flag is easily accessible as a boolean parameter to the
org.apache.xml.security.signature.XMLSignature constructor. See https://github.com/apache/santuario-java/blob/53221e7adf19317fb347ee611c9f4b4d035799ec/s rc/main/java/org/apache/xml/security/signature/XMLSignature.java#L377​ .
1 parent 560d41d commit 84c1730

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

  • core/src/main/java/com/onelogin/saml2/util

core/src/main/java/com/onelogin/saml2/util/Util.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -879,7 +879,7 @@ public static Boolean validateSignNode(Node signNode, X509Certificate cert, Stri
879879
org.apache.xml.security.Init.init();
880880

881881
Element sigElement = (Element) signNode;
882-
XMLSignature signature = new XMLSignature(sigElement, "");
882+
XMLSignature signature = new XMLSignature(sigElement, "", true);
883883

884884
if (cert != null) {
885885
res = signature.checkSignatureValue(cert);

0 commit comments

Comments
 (0)