Skip to content
  • James Edwards-Jones's avatar
    Obey GitLab.com group SAML enabled? setting · 63f98437
    James Edwards-Jones authored and Yorick Peterse's avatar Yorick Peterse committed
    Previously we weren't checking this when visiting the /sso page,
    or when hitting a callback. This is both incorrect behaviour and
    a security issue as it can be used to join a group.
    
    We don't check this on metadata endpoints still, since they are
    used before SAML is configured for the group.
    63f98437