๐Ÿ”‘ Test IdP not signed in

Failure injection

Make the IdP misbehave in exactly one way and check that your SP notices. These toggles are global and persist in data/chaos.json.

SAML

pre-sign faults are signed correctly but wrong on the merits — they test your SP's semantic validation. post-sign faults break the signature itself — they test its cryptographic validation. Confusing the two is how a homemade test IdP ends up proving nothing.

Currently active: 0