Idea Summary
When using SAML Authentication, a full SAML XML response displays in the browser after a user attempts to login with incorrect password more than 3 times. There should be a way to suppress this to prevent verbose error messages being displayed to the user which could assist attackers attempting to exploit another vulnerability.
Use Case
This would be beneficial in a production environment.
Preferred Solution (Optional)
Create a setting that would allow the suppression of detailed SAML XML responses.