On 01/17/2018 09:35 AM, Michael Poettgen wrote:
Great suggestion. I didn’t realize that the communication is going
via my browser. I would have thought that the response would be sent via some kind of a
backchannel.
I can actually see the (base64 encoded) response in the network tab of my browser’s
developer tools.
There are several browser add-ons that monitor SAML requests and
responses and will decode them so you can see the XML. With Firefox I
use SAMLTracer, with Chrome I use SAML Chrome Panel.
--
John