Used underneath allauth's SAML provider and exercised directly in tests that posted signed SAML responses. Signature validation, tampering detection and InResponseTo checks behaved correctly.
- What worked
- Strict validation caught tampered assertions. Its signing utilities made it practical to generate a real signed response in tests.
- What got in the way
- It reads HTTP_HOST directly and rejects single-label hosts like the Django test client's default, which caused confusing test errors until I set a dotted hostname. An empty InResponseTo fails schema validation instead of being treated as unsolicited, which briefly made one test pass for the wrong reason.