Identity Federation

zhaoxuya520/reverse-skill/skills/identity-federation

by zhaoxuya520cab634bd855fNo license40K starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 2 weeks ago

Use for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.

Instructions onlySecurity
AI-generated overview

Guides authorized security assessment of federated identity flows such as SAML, OIDC and OAuth2 SSO.

What it does
This skill provides a workflow for assessing federated identity systems, covering SAML assertion and signature tampering surfaces, OIDC implicit and authorization-code flows with missing PKCE, redirect_uri, state and nonce issues, and IdP/SP metadata or multi-tenant issuer confusion. It walks through mapping the User to SP to IdP to token flow, collecting OpenID configuration and SAML metadata, checking redirect_uri matching, state binding and PKCE, and reviewing session fixation and logout failures. It also lists tooling such as Burp with SAML Raider, jwt_tool and browser DevTools, and points to a companion SSO flow checklist reference.
When to use it
Use it for authorized assessment of federated identity and SSO implementations involving SAML, OIDC or OAuth2. It suits testing for SSO misconfiguration, token confusion and protocol flow mismatches, and complements API-focused JWT testing.
Requirements
No scripts are shipped; it is instructions only. It assumes authorized scope and test accounts, packet inspection tooling such as Burp with SAML Raider, jwt_tool, browser DevTools, and access to IdP administrative logs, plus the bundled reference checklist.

Identity Federation (SAML / OIDC / OAuth)

ACTION REQUIRED(读完后立刻执行)

  1. NOW: 读取 precedent-pentest;SSO 测试账号与 IdP/SP 范围入 scope
  2. NOW: 禁止锁定真实用户账户的暴力尝试
  3. NEXT: 抓包工具与文档(元数据 URL)
  4. ACT: 协议流映射 → 常见错配 → 验证

适用场景

  • SAML Response 签名/断言篡改面(经典缺陷模式)
  • OIDC 隐式/授权码 + PKCE 缺失
  • redirect_uri / state / nonce 问题
  • IdP 与 SP 元数据、多租户 issuer 混淆
  • 与 api-security JWT 攻击互补(本 skill 偏联邦与 SSO 流)

工作流

text
□ 画清:User → SP → IdP → Token → SP□ 收集:/.well-known/openid-configuration、SAML metadata□ 检查:redirect_uri 精确匹配、state 绑定、PKCE□ 检查:SAML 签名覆盖范围、algorithm 降级□ 会话固定与登出失效

工具链

工具用途
Burp + SAML Raider 等断言编辑(授权)
jwt_toolJWT 段
浏览器 DevTools重定向链
IdP 管理日志审计

参考

  • references/sso-flow-checklist.md
  • ../api-security/ ../windows-ad/(企业 IdP)

路由上下文

上游: MASTER R37
下游: 纯 API JWT → api-security;云 IdP → cloud-k8s

任务完成自检

  • 是否映射完整 SSO 流?
  • 每个 Finding 是否有复现与影响?
  • Checklist?

Source and attribution

Source:zhaoxuya520/reverse-skillinskills/identity-federationat commitcab634b

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal