Skip to content

Add regression test for return parameter on SP-bound SAML response - #2123

Merged
kayjoosten merged 1 commit into
mainfrom
test/relaystate-return-sp-post
Oct 1, 2026
Merged

kayjoosten merged 1 commit into
mainfrom
test/relaystate-return-sp-post

Conversation

@kayjoosten

Copy link
Copy Markdown
Contributor

What

Extends the RelayState Behat scenarios in Bindings.feature to also assert that the return parameter is absent from the SAML POST sent back to the SP, alongside the existing RelayState checks.

Why

Only RelayState had test coverage in the SAML POST to the SP. The return parameter had none, so a regression reintroducing an empty return field (previously fixed for the Pega Engine API issue, #1497) would go unnoticed.

Details

  • return is only ever set internally during the consent flow; by the time the response reaches the actual SP it is (by design, since the 2018 fix) never present. This PR adds an explicit assertion for that behavior to each of the six RelayState scenarios, reusing the existing generic The process form should not have the "..." field step.
  • No application code changes; test-only.

Testing

Ran the full default Behat suite locally in the Docker dev environment: 300 scenarios / 5563 steps, all passing.

Closes #2056

# If applied, this commit will
extend the Bindings behat scenarios so the return parameter is
verified alongside RelayState for every SAML flow that posts a
response back to the SP.

# Why is this change needed?
Prior to this change, only RelayState was checked in the SAML POST
sent back to the SP. The return parameter had no equivalent coverage,
so a regression that reintroduces an empty return field (previously
fixed for the Pega Engine API issue) would go unnoticed.

# How does it address the issue?
This change adds an assertion to each of the six RelayState scenarios
in Bindings.feature confirming the process form has no return field
when it is posted to the SP, reusing the existing generic process-form
field step definitions.

# Provide links to any relevant tickets, articles or other resources
Closes #2056
@kayjoosten
kayjoosten merged commit 01bf9b1 into main Oct 1, 2026
2 checks passed
@kayjoosten
kayjoosten deleted the test/relaystate-return-sp-post branch October 1, 2026 08:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add tests for presence of RelayState and return parameters sent to the SP

2 participants