From 7359bd5949f3b7fedfe98a33ba70c413afe490f9 Mon Sep 17 00:00:00 2001 From: Marcus Da Coregio Date: Wed, 10 Aug 2022 09:36:28 -0300 Subject: [PATCH] Move SAML Post inline javascript to script tag To avoid relying on HTML event handlers and adding unsafe-* rules to CSP, the javascript is moved to a \n"); html.append(""); return html.toString(); } diff --git a/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java b/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java index b5da703eb7b..230cc6572e1 100644 --- a/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java +++ b/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java @@ -216,7 +216,7 @@ private String createSamlPostRequestFormData(String location, String saml, Strin html.append("\n"); html.append("\n").append(" \n"); html.append("