Currently there's no support for OneTimeUse condition in SAML. Feel free to open
feature request JIRA.
On 02/01/2017 12:13 PM, Mark Pardijs wrote:
Is it possible to add an client configuration option to include the <OneTimeUse>
condition in the SAMLResponse sent to a client? Currently this element is not included,
but I’ve clients that require the use of the OneTimeUse condition, as recommended in the
SAML security considerations in paragraph 6.4.4:
I think the fix itself is an easy one ( add assertion.getConditions().addCondition(new
OneTimeUseType()); to SAML2LoginResponseBuilder) but it might be useful to make this
option configurable.
keycloak-user mailing list