Weave Code
Code Weaver
Helps Laravel developers discover, compare, and choose open-source packages. See popularity, security, maintainers, and scores at a glance to make better decisions.
Feedback
Share your thoughts, report bugs, or suggest improvements.
Subject
Message

Lightsaml Laravel Package

litesaml/lightsaml

View on GitHub
Deep Wiki
Context7
5.1.0

Security

  • Reject Responses with duplicate assertion IDs (#114)
  • Reject assertions with missing or empty ID (#117) (#118)

Bug Fixes

  • Throw LightSamlBindingException instead of TypeError in getBindingByRequest() (#116)

Full Changelog: https://github.com/litesaml/lightsaml/compare/5.0.1...5.1.0

5.0.1

Security

  • Reject XML Signature Wrapping (XSW) attacks in SignatureXmlReader (#113)

LightSAML 5.0.0 was vulnerable to an XML Signature Wrapping (XSW) attack allowing an attacker who has captured one genuine signed assertion to have LightSAML accept a fully attacker-authored assertion as IdP-signed, leading to authentication bypass and privilege escalation.

The fix enforces two invariants before signature validation: the ds:Signature parent element must carry the ID referenced by the fragment URI, and that ID must be unique in the document.

Full Changelog: https://github.com/litesaml/lightsaml/compare/5.0.0...5.0.1

5.0.0

Breaking Changes

  • Remove Pimple bridge and unused implementations (#107)
  • Replace symfony/http-foundation with PSR-7 interfaces (#109)
  • Bump minimum PHP requirement to 8.4
  • Add strong typing to method parameters and return values (#110)
  • Remove deprecated Serializable interface from state classes (#111)
  • Enforce strict typing and reach PHPStan level 6 zero errors (#112)

Continuous Integrations

  • Modernize CI workflows

Documentation

  • Recommend litesaml/saml wrapper for high-level usage

Full Changelog: https://github.com/litesaml/lightsaml/compare/4.7.0...5.0.0

4.7.0

Features

  • Add RSA-PSS certificate and SAML signature support (#102)
  • Include AssertionConsumerServiceURL in outbound AuthnRequest (#103)
  • Return SamlMessage from binding receive() method (#105)

Bug Fixes

  • Bump dependencies to address security vulnerabilities (#101)
  • Use SHA256 as default signing algorithm instead of SHA1 (#104)
  • Use SignatureXmlReader instead of abstract Signature in RoleDescriptor deserialization (#106)

Full Changelog: https://github.com/litesaml/lightsaml/compare/4.6.1...4.7.0

Weaver

How can I help you explore Laravel packages today?

Conversation history is not saved when not logged in.
Prompt
Add packages to context
No packages found.
besmartand-pro/php-quality-config
sentix/ai-chatbot
terminal42/code-quality-tools
codifyo/ts-generator-bundle
testo/fiber
mintobit/jobqueue
a4sex/maintenance-bundle
a4sex/entity-date-update
a4sex/client-identifier
a4sex/base-utilites
a4sex/key-value-storage
a4sex/micro-status
chilldev/dependency-injection-extra
datinglibre/datinglibre-app-api
biberltd/corebundle
bricre/symfony-bundle-test
biberltd/logbundle
dominium/http-adapter-bundle
dominium/google-analytics
a4sex/auto-clean-entity