Thijs Kinkhorst
Thijs Kinkhorst
If you follow the installation steps in the manual it does not currently work. This is because they are spilt over domserver and judgehost and it's not currently possible to...
According to `ykman`: ``` WARNING: The use of this command is deprecated and will be removed! Replace with: ykman piv access unblock-pin ```
We had a production SP configured with not checking any response or assertion signature at all. The warning was logged, but not noticed. This is quite undesirable, in other words,...
When _filter resources_ is enabled, I still see (gray) lines for some png, css and js. I strongly suspect these are resources that return an 304 Not Modified HTTP response....
When there's a problem with the CSP, the test now outputs: "You send this CSP: " and then many paragraphs of text with all the requirements for the CSP. It's...
Since 4e15051a7eef948637c2a42c095f358040b0d6be (2009) the `$instancename` parameter to `Configuration::getInstance()` [is deprecated](https://github.com/simplesamlphp/simplesamlphp/blob/4b959dff6633f7d978475c3fc41452247071e89a/src/SimpleSAML/Configuration.php#L331) with no clear course of action. Either we should remove it now after being deprecated for so long, or just...
As listed in the OASIS standard
…, useful for testing
The CSP is cached a long time so you must take due precautions and add any new asset host to it at least a week before you make the change....