diff options
author | Richard van der Hoff <1389908+richvdh@users.noreply.github.com> | 2018-12-07 13:11:11 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2018-12-07 13:11:11 +0100 |
commit | c7401a697f1ee3410b860afd8686f8bb012a8dce (patch) | |
tree | 5de0676006c902fe90ccebb6856b32371a5bcb76 /changelog.d/4267.feature | |
parent | Factor SSO success handling out of CAS login (#4264) (diff) | |
download | synapse-c7401a697f1ee3410b860afd8686f8bb012a8dce.tar.xz |
Implement SAML2 authentication (#4267)
This implements both a SAML2 metadata endpoint (at `/_matrix/saml2/metadata.xml`), and a SAML2 response receiver (at `/_matrix/saml2/authn_response`). If the SAML2 response matches what's been configured, we complete the SSO login flow by redirecting to the client url (aka `RelayState` in SAML2 jargon) with a login token. What we don't yet have is anything to build a SAML2 request and redirect the user to the identity provider. That is left as an exercise for the reader.
Diffstat (limited to 'changelog.d/4267.feature')
-rw-r--r-- | changelog.d/4267.feature | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/changelog.d/4267.feature b/changelog.d/4267.feature new file mode 100644 index 0000000000..da36986e2b --- /dev/null +++ b/changelog.d/4267.feature @@ -0,0 +1 @@ +Rework SAML2 authentication |