Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

saml: capture + diff legacy assertion for NameID continuity

未关闭
#52 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
35/100
Issue 类型
功能
描述清晰度
描述清楚
活跃度
冷清
技术栈
typescript

调研方向

阅读 plans/saml-idp.md 中的“Risks & Unknowns”,然后使用浏览器 DevTools 从真实的 /Slack/Login 流程中捕获 SAMLResponse。对其进行解码,并将其与同一 Person 的 /api/saml/slack/launch 的解码响应逐字段进行比较。完成的标准是只有时间戳和 ID 不同;NameID 字段、限定符和属性名称保持一致,或者识别出需要修复的迁移问题。

由索引模型根据 Issue 内容生成。

描述

Capture a real assertion emitted by the legacy laddr emergence-slack code in production, and diff against the assertion the new IdP would emit for the same user.

Surfaced by the saml-idp plan's closeout (PR #49). Per plans/saml-idp.md#risks--unknowns, this is "the single highest-stakes thing in this plan" — the v1 IdP claims to preserve NameID stability for every existing Slack account through cutover. The way to actually prove that is:

  1. Browser-side: capture a laddr-emitted SAMLResponse during a real /Slack/Login flow (browser devtools → Network tab → look at the POST to slack.com/sso/saml — the SAMLResponse is in the form body, base64-encoded)
  2. Decode the XML
  3. For the same Person, build the v1 IdP's response (via /api/saml/slack/launch) and decode
  4. Diff field-by-field. Acceptable diffs: timestamps, IDs. Unacceptable: NameID.Value, NameID.Format, NameQualifier, SPNameQualifier, attribute names.

If the diff turns up a NameID delta for any user, we need to fix migration before cutover.

Out of band of the v1 PR; needs:

  • Access to a logged-in legacy laddr account
  • Coordination with that user
主要语言
TypeScript
星标
1
派生
1
平均合并
1 天 20 小时
30 天内合并 PR
25

贡献指南

这个仓库没有索引到贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

CodeForPhilly/codeforphilly-ng 的其他 Issue

查看 CodeForPhilly/codeforphilly-ng 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。