Skip to main content

Looking ahead to the Spring '23 release, I've tested out the "Upgrade SAML Single Sign-On Framework" in a sandbox. However, my team is questioning what the this line in the release note means:

"Some single sign-on (SSO) URLs are now encoded. For service provider-initiated SSO, the Identity Provider URL and Assertion Consumer Service (ACS) URL are encoded."

Can anyone clarify?

1 个回答
  1. 今天,06:49

    Hi Sara, “encoded” here means Salesforce is URL-encoding certain parts of the SAML URLs/parameters before sending them as part of the SSO request. 

     

    For example, characters such as ?, &, =, spaces, etc. can be represented in an encoded form so they’re interpreted correctly as part of the URL rather than as separators or special characters. 

     

    For SP-initiated SSO, the change applies to the Identity Provider URL and ACS URL. Salesforce also encodes the Single Logout Endpoint and Relay State for SLO configurations. 

     

    For most Salesforce configurations, there shouldn't be anything you need to change. The main concern is if the external IdP or SAML application has custom logic that expects the URLs in their previous, unencoded form. Salesforce recommends testing existing SAML integrations before enabling the update because third-party integrations can be affected. 

     

    So, if your SSO integration is working normally after enabling the update, there shouldn't be any action required. 

0/9000