From 00302c80adb0a67d0a3d218022b8b647053d4137 Mon Sep 17 00:00:00 2001 From: Marcus Da Coregio Date: Wed, 10 Aug 2022 09:36:28 -0300 Subject: [PATCH] Move SAML Post inline javascript to script tag To avoid relying on HTML event handlers and adding unsafe-* rules to CSP, the javascript is moved to a \n"); html.append(""); return html.toString(); } diff --git a/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java b/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java index 9b068320fc..ce4b8f8ca1 100644 --- a/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java +++ b/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java @@ -200,7 +200,7 @@ public final class Saml2LogoutRequestFilter extends OncePerRequestFilter { html.append("\n"); html.append("\n").append(" \n"); html.append("