Missing check for Assertion - Attribute Method of SubjectConfirmation element.
i1990jain opened this issue · comments
Rishabh Jain commented
The value of the Method attribute in the SubjectConfirmation element when there is an Assertion element in the response. There is no exception raised when the value is empty or not what is required.
<saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:diversodabearer">