[JIRA] Commented: (SSPCPP-417) redirectErrors configuration attribute does not handle relative URLs
Scott Cantor (JIRA)
noreply at shibboleth.net
Wed Jan 18 01:36:26 GMT 2012
[ https://issues.shibboleth.net/jira/browse/SSPCPP-417?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13771#comment-13771 ]
Scott Cantor commented on SSPCPP-417:
-------------------------------------
I believe the documentation is actually wrong, it does not currently support relative URLs. I'll fix that. But I think what you're seeing isn't "redirection" to that URL, but the normal error handling template. If you get it to attempt to use a relative URL, the XSS sanitation kicks in and throws an exception inside the error handling code, and Apache throws a Server Error, with the exception in the Apache log.
I think your mistake is that your error handler setting is being applied to the content, but not the handlerURL(s), specifically the ACS. That won't work, since the effective URL being processed during the error is the ACS. Generally the error handler is an application-wide setting that has to apply to all the resources in the app, so usually it's set at the same level as the applicationId would be, or globally.
> redirectErrors configuration attribute does not handle relative URLs
> --------------------------------------------------------------------
>
> Key: SSPCPP-417
> URL: https://issues.shibboleth.net/jira/browse/SSPCPP-417
> Project: Shibboleth SP - C++
> Issue Type: Bug
> Components: Configuration, Error Handling
> Affects Versions: 2.4.3
> Environment: CentOS 5.7, Shibboleth RPMs 2.4.3-2.2, Apache 2.2.3-53
> Reporter: Terrence G Fleury
> Assignee: Scott Cantor
> Labels: Session
>
> Using documentation found at https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPErrors , I attempted to use the "redirectErrors" attribute with a relative URL. When using an absolute URL such as 'redirectErrors="https://example.org/script.php"', errors were redirected to the 'script.php' handler as expected. When using a relative URL such as 'redirectErrors="script.php"', errors were instead redirected to "https://example.org/Shibboleth.sso/SAML2/POST". I tried several variations such as "/script.php", "../script.php", "/../script.php", etc., but none of them worked. So either the documentation is incorrect (i.e. relative URLs are not allowed), or there is a bug in the code which handles relative URLs.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list