NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1529 most downloaded on PyPI
Saml Python Toolkit. Add SAML support to your Python software using this library
Last release 3 years ago
no release in 18 months
Release timing varies
gaps range from 2 weeks to 1.2 years
Nearly every release is documented
notes for 27 of 28 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
28 releases · first in 2015
Fix WantAuthnRequestsSigned parser
Remove version restriction on lxml dependency
One column per quarter.
#297 Don't require yanked version of lxml. #298 Add support for python 3.10 and cleanup the GHA. #299 Remove stats from coveralls removed as they are
Set sha256 and rsa-sha256 as default algorithms
#276 Deprecate server_port from request data dictionary
Remove the dependency on defusedxml
Fix bug on LogoutRequest class, get_idp_slo_response_url was used instead get_idp_slo_url
Added custom lxml parser based on the one defined at xmldefused. Parser will ignore comments and processing instructions and by default have deactivat
Allow any number of decimal places for seconds on SAML datetimes
Set true as the default value for strict setting
Adjusted acs endpoint to extract NameQualifier and SPNameQualifier from SAMLResponse. Adjusted single logout service to provide NameQualifier and SPNa
Add support for Subjects on AuthNRequests by the new name_id_value_req parameter
Security improvements. Use of tagid to prevent XPath injection. Disable DTD on fromstring defusedxml method
Add ID to EntityDescriptor before sign it on add_sign method.
Changelog:
Fix vulnerability CVE-2017-11427. Process text of nodes properly, ignoring comments
Changelog:
Improve decrypt method, Add an option to decrypt an element in place or copy it before decryption.
Use defusedxml that will prevent XEE and other attacks based on the abuse on XMLs. (CVE-2017-9672)
Fix issue related with multicers (multicerts were not used on response validation)
Changelog:
Publish KeyDescriptor[use=encryption] only when required
Changelog:
* Fix p3 compatibility
This version includes improvements oriented to help the developer to debug.
This version includes improvements oriented to help the developer to debug.
Changelog:
- #30 Fix a bug on signature checks
This version includes a security patch that contains extra validations that will prevent signature wrapping attacks.
This version includes a security patch that contains extra validations that will prevent signature wrapping attacks.
Changelog:
Change the decrypt assertion process.
Changelog:
Fix Metadata XML (RequestedAttribute)
Changelog:
Allow AuthnRequest with no NameIDPolicy.
Changelog:
Make AttributeStatements requirement optional
Changelog:
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →