A SAML response verifies and one ACS path still rejects it
The signature is valid, but destination enforcement fails because the app sees a different external URL than the proxy emitted.
SecurityIntermediate
A SAML ACS route verifies signatures and still fails destination checks
The assertion is valid, but the service compares it against a URL missing the external port.
SecurityIntermediate
A SAML logout works on the main domain and loops on the callback path
Login succeeds, yet logout or callback validation fails on one route because the service provider reconstructs a different external URL than the browser used.
SecurityIntermediate
A SAML response validates and still fails only in browsers
The assertion is fine, but the browser drops the session cookie the ACS flow expects to correlate.