I'm asking this before being able to incorporate this feature:
the master branch / https://github.com/droath/samlauth/commit/c6e1c16308c8643fe560f760eb0d2e... adds an option to select "entity ID types" and a new type for "URL".
I'm not sure what to think about that. an Entity ID is supposed to be static, and I'm not sure if you should ever be making it dependent on what your base URL happens to be.
What is the application of this? (Same config over different sites?)
It seems to me like this feature was maybe introduced because of an earlier assumption that the metadata URL should be equal to the entity ID. But it shouldn't. The entity ID can be any string, in 1.x / 2.x-alpha0.

Comments
Comment #2
roderikComment #3
seanbThe use cases I see atm also require a fixed Entity ID, but if there is a good reason to add this, it is not a major change. Custom should probably be the default though.
Comment #4
roderikI'm not against adding it, but I am against adding it without good documentation on the "why"s. It should be clear what this option does and why; otherwise
* the user just gets confused with all the different choices
* things become unmaintainable. And we should aim for stability.
---
On a vaguely related topic:
The 'droath' branch has completely removed the "Unique identifier attribute" config value, and now registers $onelogin_samlauth->getNameId() for user registration in the authmap / passing to loginRegister() as a unique ID.
Now, I admit to not knowing a lot of SAML details myself... but it seems to me that this won't fly if your NameID format is "transient". (See e.g. the yellow box at http://stackoverflow.com/questions/11693297/what-are-the-different-namei... ).
We're not going to be committing 'frivolous' changes like these. It may be a nice option to not have to specify your unique ID attribute, and I'll keep it in mind. But it will be committed as an option with documentation in the form of at least a line of help text under the "Unique identifier attribute" config element.
(PS I'm still slow as mud, progressing a tiny bit every night.)
Comment #5
roderikI have now isolated the changes for the Entity ID type, plus for using the NameID from the SAML assertion as unique attribute, and ported them to the 2.x branch.
This needs a bit of work. The two things also don't necessarily have anything to do with each other... but I'm not going to push either of these changes forward, until someone tells me they need it and why.
Comment #6
roderikMy thoughts/concerns about NameIDs are now better formed, and outlined in #3211380: NameID support.
And 'Entity ID type' is not a thing. So, closing this.