I used to maintain a legacy public IdP with a bespoke saml implementation that predated almost anything and was a nightmare to work with. I always wanted to migrate to one login. Luckily I left that job before embarking in such a nightmarish project.
I mean … how else would you check a signature? You have to have the data to validate the signature.
In SAML you sign a (potentially attacker controlled) subset after normalization. So a lot of saml bugs come down to the attacker adding things that aren't covered by the signature. Sometimes this means appending or prepending stuff, but my favourite is adding comments which can alter the interpretation of the xml document (as it splits text nodes) but doesn't alter the signature.
It's an absolute dumpster fire.
So it is possible to have an XML signature that points to an element that does not include some important piece of data.
You would be shocked (or, if you’re in the security space at all, not even remotely shocked) to learn that a comical number of SAML implementations verified the signature and then just treated the whole doc as if it was trusted, even if the signed part had nothing to do with the document as a whole.
Email's in a bad situation with regards to this because every intermediate server is expected to mangle the message and the headers, so the only way to consistently sign something is to make it a marked up encoded block the way PGP does.