https://sonarly.com/issue/41466?type=bug SAML setup is blocked for some organizations because IdP metadata files are rejected client-side as “Invalid File”. The user cannot complete SSO onboarding from the file upload flow. Fix: Implemented a targeted frontend parser relaxation so valid IdP metadata variants are no longer rejected as “Invalid File” before the user can proceed. What changed: 1) `parseSAMLMetadataFromXMLFile` now resolves XML nodes by `localName` instead of a hardcoded prefix allowlist (`md/ns0/ns2/dsig/ds`), so metadata with arbitrary namespace prefixes can be parsed. 2) SSO URL extraction no longer requires the HTTP-Redirect binding specifically. It now selects the first `SingleSignOnService` `Location` that is a valid URL. 3) `entityID` validation was relaxed from `z.url()` to non-empty string (`z.string().min(1)`), allowing valid SAML issuer formats like `urn:...` to parse successfully and prefill the form instead of failing file import. 4) Added a unit test that covers non-standard prefixes, POST-only SSO endpoint metadata, and a non-URL entityID to ensure this regression is prevented. This keeps failures for truly malformed XML/cert data while accepting legitimate metadata variants that were previously blocked in the upload flow. Authored by Sonarly by autonomous analysis (run 47281).
The #1 Open-Source CRM
Website ·
Documentation ·
Roadmap ·
Discord ·
Figma
Why Twenty
Twenty gives technical teams the building blocks for a custom CRM that meets complex business needs and quickly adapts as the business evolves. Twenty is the CRM you build, ship, and version like the rest of your stack.
Learn more about why we built Twenty
Installation
Cloud
The fastest way to get started. Sign up at twenty.com and spin up a workspace in under a minute, with no infrastructure to manage and always up to date.
Build an app
Scaffold a new app with the Twenty CLI:
npx create-twenty-app my-app
Define objects, fields, and views as code:
import { defineObject, FieldType } from 'twenty-sdk/define';
export default defineObject({
nameSingular: 'deal',
namePlural: 'deals',
labelSingular: 'Deal',
labelPlural: 'Deals',
fields: [
{ name: 'name', label: 'Name', type: FieldType.TEXT },
{ name: 'amount', label: 'Amount', type: FieldType.CURRENCY },
{ name: 'closeDate', label: 'Close Date', type: FieldType.DATE_TIME },
],
});
Then ship it to your workspace:
npx twenty app:publish --private
See the app development guide for objects, views, agents, and logic functions.
Self-hosting
Run Twenty on your own infrastructure with Docker Compose, or contribute locally via the local setup guide.
Everything you need
Twenty gives you the building blocks of a modern CRM (objects, views, workflows, and agents) and lets you extend them as code. Here's a tour of what's in the box.
Want to go deeper? Read the User Guide for product walkthroughs, or the
Documentation for developer reference.
|
|
|
|
|
|
Stack
TypeScript
Nx
NestJS, with BullMQ,
PostgreSQL,
Redis
React, with Jotai, Linaria and Lingui
Thanks
Thanks to these amazing services that we use and recommend for UI testing (Chromatic), code review (Greptile), catching bugs (Sentry) and translating (Crowdin).
Join the Community
Star the repo ·
Discord ·
Feature requests ·
Releases ·
X ·
LinkedIn ·
Crowdin ·
Contribute





