Flow 03 · Workforce
The assertion comes back through the browser.
SAML 2.0 is still how a lot of workforce SaaS gets its users. The identity provider signs a statement, the browser carries it, and the app has to be picky about who it’s for and how long it’s good.
Watch for
- In the usual POST binding there’s no server-to-server token call. The browser is the courier.
- Sign the assertion itself. A signature on the outer response can leave the statement you care about unprotected.
- Audience, recipient,
InResponseTo, and a short clock window are what make that courier acceptable.
Failure modes
- A validity window of hours. Someone who captured the POST has a working login until it ends.
- Skipping the audience check because you only have one app today. You’ll have two.
- Mapping
NameIDby email without deciding which identity provider you’re willing to believe for that app.