Skip to Main Content
Feature Request FR-4486
Product Area Security
Status CLOSED

1 Voters

Suppress Apex SAML XML response from displaying after Authentication Failed

lee.gunderson Public
· May 30 2025

Idea Summary
When using SAML Authentication, a full SAML XML response displays in the browser after a user attempts to login with incorrect password more than 3 times. There should be a way to suppress this to prevent verbose error messages being displayed to the user which could assist attackers attempting to exploit another vulnerability.

Use Case
This would be beneficial in a production environment.

Preferred Solution (Optional)
Create a setting that would allow the suppression of detailed SAML XML responses.

This idea submission relates to an APEX bug and will be tracked in our bug system.