From 0c96989cbe13532e70d0ec0d4b9c5db97387addf Mon Sep 17 00:00:00 2001 From: Marcus Da Coregio Date: Mon, 19 Sep 2022 15:46:23 -0300 Subject: [PATCH] Move script tag into body element Closes gh-11879 --- .../filter/Saml2WebSsoAuthenticationRequestFilter.java | 2 +- .../web/authentication/logout/Saml2LogoutRequestFilter.java | 4 ++-- .../Saml2RelyingPartyInitiatedLogoutSuccessHandler.java | 4 ++-- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/servlet/filter/Saml2WebSsoAuthenticationRequestFilter.java b/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/servlet/filter/Saml2WebSsoAuthenticationRequestFilter.java index e31ed167c0..4aced5f64a 100644 --- a/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/servlet/filter/Saml2WebSsoAuthenticationRequestFilter.java +++ b/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/servlet/filter/Saml2WebSsoAuthenticationRequestFilter.java @@ -268,8 +268,8 @@ public class Saml2WebSsoAuthenticationRequestFilter extends OncePerRequestFilter html.append(" \n"); html.append(" \n"); html.append(" \n"); + html.append(" \n"); html.append(" \n"); - html.append(" \n"); html.append(""); return html.toString(); } diff --git a/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java b/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java index 230cc6572e..af08f0b261 100644 --- a/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java +++ b/saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/provider/service/web/authentication/logout/Saml2LogoutRequestFilter.java @@ -219,7 +219,7 @@ public final class Saml2LogoutRequestFilter extends OncePerRequestFilter { .append("content=\"script-src 'sha256-t+jmhLjs1ocvgaHBJsFcgznRk68d37TLtbI3NE9h7EU='\">\n"); html.append(" \n"); html.append(" \n"); - html.append(" \n"); + html.append(" \n"); html.append("