Hi all, I believe enabling the *script-src* Content Security Policy in Apache will break SAML.
https://content-security-policy.com/script-src/ "The execution of all JS event handlers from inline HTML markup are blocked default, onclick, onload, onmouseover, onsubmit, etc. You can get them to work via a 'unsafe-hashes' source list expression, however that is only supported on CSP Level 3 browsers." The callback from CAS through to the SAML SP fails because it contains some of these handlers. I have yet to try it, but possibly the *unsafe-hashes* policy could be used. But, it is not the safe or recommended way. They recommend refactoring the offending code. Page loaded from https://cas.server.com/idp/profile/SAML2/Callback?entityId=ENTITYID&ticket=TICKET <!DOCTYPE html> <html> <head> <meta charset="utf-8" /> </head> <body onload="document.forms[0].submit()"> <noscript> <p> <strong>Note:</strong> Since your browser does not support JavaScript, you must press the Continue button once to proceed. </p> </noscript> <form action="https://saml.sp.com/Saml/SSO" method="post"> <div> <input type="hidden" name="RelayState" value="RELAYSTATE;"/> <input type="hidden" name="SAMLResponse" value="SAMLRESPONSE"/> </div> <noscript> <div> <input type="submit" value="Continue"/> </div> </noscript> </form> </body> </html> -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/40ab7a36-8f57-41b0-afb1-ce790d9df43an%40apereo.org.
