summaryrefslogtreecommitdiffstats
path: root/docs/simplesamlphp-authsource.md
diff options
context:
space:
mode:
authorJaime Pérez <jaime.perez@uninett.no>2016-07-28 17:14:46 +0200
committerJaime Pérez <jaime.perez@uninett.no>2016-07-28 17:14:46 +0200
commit6d215c0b4ebce4957e4541f2cb6cb0bcb154a438 (patch)
tree59b9324f69072a8575c30a1b2fffbbef8f74ac1f /docs/simplesamlphp-authsource.md
parentf261dfc1463ce867838b947f763470c61774e385 (diff)
downloadsimplesamlphp-6d215c0b4ebce4957e4541f2cb6cb0bcb154a438.zip
simplesamlphp-6d215c0b4ebce4957e4541f2cb6cb0bcb154a438.tar.gz
simplesamlphp-6d215c0b4ebce4957e4541f2cb6cb0bcb154a438.tar.bz2
Use AttributeValue serializable objects instead of dumping manually the XML contents.
This way, we avoid completely any possible XXE attack, and simplify the code as we don't need to deal directly with the DOM. The entire AttributeValue will be saved to the backend as XML, and then recovered back when unserializing.
Diffstat (limited to 'docs/simplesamlphp-authsource.md')
0 files changed, 0 insertions, 0 deletions