SAML 2.0 Config
samlFlowIdpSettings) samlFlowSpSettings) enableSingleLogoutOnSps) customSpSsoInitializationUri) The URI to start or continue the correct authentication flow after receiving an assertion from the Identity Provider (either using IdP- or SP-initiated SSO).
Must only be configured when using a custom SPA.
Relative URIs not starting with a slash are resolved against the current context path.
When customized and behind an Airlock Gateway (WAF), a "URL Encryption Exception" must be configured.
customLogoutUri) The URI to start the logout process in the UI.
This is used during IdP-initiated Single-Logout (the logout is started by an Identity Provider). In this case, the browser must first be redirected to the UI in order to start the regular logout before being able to finish the SAML 2.0 Single-Logout.
Must only be configured when using a custom SPA.
Relative URIs not starting with a slash are resolved against the current context path.
When customized and behind an Airlock Gateway (WAF), a "URL Encryption Exception" must be configured.
customLogoutResumeUriPattern) During SP-Initiated Single-Logout (SLO), the SPA has to send the location where to resume the logout process after SAML 2.0 Single-Logout has been finished using a "Location" URL parameter.
If not configured, the standard URL for logout resume in the Loginapp UI (ui/app/auth/logout/resume) will be used.
That absolute location will be validated against this pattern.Must only be configured when using a custom SPA.
If behind an Airlock Gateway (WAF), a "URL Encryption Exception" must also be configured for this URL.
samlFederationConfig)
type: Saml
id: Saml-xxxxxx
displayName:
comment:
properties:
customLogoutResumeUriPattern:
customLogoutUri:
customSpSsoInitializationUri:
enableSingleLogoutOnSps: true
samlFederationConfig:
samlFlowIdpSettings:
samlFlowSpSettings: