Skipping query parameters while building SSO redirect URL

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

Skipping query parameters while building SSO redirect URL

kjayashankar
This post was updated on .
Hi,

I'm using opensaml 2.6 for building the SSO redirect URL. Here is the strange thing that I noticed in HTTPRedirectDeflateEncoder.java

URLBuilder urlBuilder = new URLBuilder(endpointURL);

        List<Pair<String, String>> queryParams = urlBuilder.getQueryParams();
        queryParams.clear();

        if (messagesContext.getOutboundSAMLMessage() instanceof RequestAbstractType) {
            queryParams.add(new Pair<String, String>("SAMLRequest", message));
        }

Why are we removing the query parameters from the endpoint URL ??