GitHub
05/19/2026, 10:36 PM<https://github.com/jmpsec/osctrl/tree/main|main> by javuto
<https://github.com/jmpsec/osctrl/commit/3c7f81438a2008813d1fa2b7908aa75cf8ee8db0|3c7f8143> - saml: pkg/auth/saml protocol package + JIT auth-source plumbing
<https://github.com/jmpsec/osctrl/commit/a0e29e72debdcde412ce34e9a5ceaae21be7615a|a0e29e72> - saml: wire cmd/api handlers + routes + SPA login button
<https://github.com/jmpsec/osctrl/commit/5ea20206a518772585327f319fee1e7da1225aa3|5ea20206> - saml: adopt OAuthState/Nonce split (sync with OIDC)
<https://github.com/jmpsec/osctrl/commit/9f4685c23ddd266b3ce76dde881b203709bf5538|9f4685c2> - saml: enforce InResponseTo correlation (close S7) + log private errors
<https://github.com/jmpsec/osctrl/commit/23bdab0c9b6d89b10ed17ea3167e0476bd6f538c|23bdab0c> - saml: fix SAML logout — gate IdP fields by auth_source + ForceAuthn
<https://github.com/jmpsec/osctrl/commit/e70452ad10d466c41b3498f3097c4c9e70bc9ed6|e70452ad> - saml: HTTPS-ready state cookie + Auth0 username attribute + per-session logout
<https://github.com/jmpsec/osctrl/commit/9971df25ae8a8df2c039e4bbc1524292338282b8|9971df25> - saml: sign AuthnRequests (close AuthnRequestsSigned=false finding)
<https://github.com/jmpsec/osctrl/commit/2dd4c8cd7f49185def16b38e216214711eb7b3ef|2dd4c8cd> - Merge pull request #831 from alvarofraguas/pr/saml-api-spa
jmpsec/osctrl