Weave Code
Code Weaver
Helps Laravel developers discover, compare, and choose open-source packages. See popularity, security, maintainers, and scores at a glance to make better decisions.
Feedback
Share your thoughts, report bugs, or suggest improvements.
Subject
Message

Saml2 Laravel Package

simplesamlphp/saml2

View on GitHub
Deep Wiki
Context7
v7.0.0-rc1

This release bumps the minimum required PHP-version to 8.5 and migrates to the new PHP DOM-API that was introduced in PHP 8.4

v4.19.1

Fixed CVE-2025-66475

v6.0.0

Following up on v5 this is another intermediate step that changes the interface. A major change here is that instead of passing a 'string' to a method and validate that the string is a valid URI, we now pass an AnyURIValue object, drastically reducing the overhead of validating strings multiple times.

Appropriate to use for people who need to generate/parse SAML 2.0 messages/metadata, or use bindings. Still no full replacement for the old v4. We plan to release a full replacement for v4 in v6.1 where we add ServiceProvider/IdentityProvider where you pass all your configuration and metadata and then those classes will do all the heavy lifting to process requests/responses according to the SAML2 specifications.

Until we release a full replacement, we will keep supporting and patching v4

v5.0.0

Version 5.0 of this library completely rewrites the library to modern standards. It is a necessary intermediate step for us to migrate away from the old v4, but it is in no way a replacement. You can still use it if your concern is just generating/parsing SAML 2.0 messages/metadata

v4.17.0

Fixes CVE-2025-27773

v4.6.10

Fix regression (missing use statement) introduced in 4.6.9.

v4.6.3
v4.1.9

Bugfix

  • Make processor aware of assertion types #240
v3.4.5

Fix an invalid assertion, leading to an InvalidArgumentException when trying to set the AssertionConsumerServiceIndex on an AuthnRequest

v4.1.7

Fix incorrect use of Issuer-class

v4.1.6

Fix a mistake in the bugfix for #229

v4.1.5

Fixes a bug in HTTPArtifact::receive (#229)

v2.3.9

This is a bugfix release of the SAML2 library, fixing a critical security issue (SSPSA 201911-01).

v3.4.2

This is a bugfix release of the SAML2 library, fixing a critical security issue (SSPSA 201911-01).

v4.1.1

This is a bugfix release of the SAML2 library, fixing a critical security issue (SSPSA 201911-01).

v4.0.0

This is a stable release of the SAML2 library.

The most significant changes are:

  • Minimum required PHP-version is bumped to 7.2
  • Fully typehinted codebase, strict_types=1
  • Updated dependencies to their latest version
  • Introduced Psalm static analysis

If you are a developer using this library as part of your application, make sure you read the Upgrade Notes

v3.4.1
  • Add support to provide private key as string in addition to file path

This is a bugfix release: v3.4.0 was accidentally based on master instead of the 3.x branch

v3.3.8
v3.3.6
  • Bugfix for SPProvidedID in NameID fromArray().
  • Bugfix for parsing mdui:Logo elements with data: URLs.
v3.3.0
  • All code has been converted to use the shorthand array syntax
  • Getter/setter methods have been added for all public properties; properties will be marked private in the next major release.
  • Added support for Conditions/AudienceRestriction/Audience in AuthnRequest (#137)
  • More unit-tests have been added
  • Upgraded dependencies
  • Calls to SimpleSAML_ have been namespaces, deprecated calls to SimpleSAML_Utilities have been replaced by their new counterparts
  • Assorted whitespace-fixes / PSR-2 fixes / minor bugfixes
v3.2.6
  • Fix invalid XML being generated for Assertion element (Signature in wrong position), introduced in v3.2.3. Thanks Dick Visser from Géant for reporting!
  • Allow to use integer type attibutes in AttributeQuery.
v3.2.5
  • More fixes to type hints.
v3.2.4
  • Revert type hints in AbstractContainer added in v3.2.3, since this might break existing implementations and thus should not have been in a minor release.
v3.2.3
  • Make Compat Logger PSR-3 compliant.
  • Be tolerant of string EPTIs instead of breaking mere parsing of those.
  • Code cleanups.
v3.2.2
  • Update the dependency on xmlseclibs
  • Add PasswordProtectedTransport to constants
v3.2.1
  • Update the dependency on xmlseclibs.
v3.2
  • Change the default signature algorithm from RSA-SHA1 to RSA-SHA256.

    Please note that this change does not remove support for RSA-SHA1. However, when passing a XMLSecurityKey to verify a signature, that key must be created with the RSA-SHA256 algorithm.

v3.1.6
  • Assertion: fix method "hasEncryptedAttributes".
  • Issuer: support to send entity Format and NameQualifier.
v3.1.5
  • Add PHP 7.2 support
  • Fix wrong class name in ECP request processing
v3.1.4
  • Fix for SSPSA 201803-01.
v2.3.8
  • Fix for SSPSA 201803-01.

Please note that this is the last 2.x release.

Weaver

How can I help you explore Laravel packages today?

Conversation history is not saved when not logged in.
Prompt
Add packages to context
No packages found.
codifyo/ts-generator-bundle
andydefer/laravel-cluster
testo/fiber
mintobit/jobqueue
a4sex/maintenance-bundle
a4sex/entity-date-update
a4sex/client-identifier
a4sex/base-utilites
a4sex/key-value-storage
a4sex/micro-status
chilldev/dependency-injection-extra
datinglibre/datinglibre-app-api
biberltd/corebundle
bricre/symfony-bundle-test
biberltd/logbundle
dominium/http-adapter-bundle
dominium/google-analytics
a4sex/auto-clean-entity
christhompsontldr/laravel-inky
spatie/mailcoach-vapor