[JIRA] Commented: (SSPCPP-417) redirectErrors configuration attribute does not handle relative URLs
Scott Cantor (JIRA)
noreply at shibboleth.net
Wed Jan 18 01:42:26 GMT 2012
[ https://issues.shibboleth.net/jira/browse/SSPCPP-417?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13772#comment-13772 ]
Scott Cantor commented on SSPCPP-417:
-------------------------------------
Ah, and now my confusion is cleared up...there are two ways to set the redirectErrors feature, one that was the original "intended" way, and the other that was added as a supplement.
The way it's supposed to work is via the <Errors> element as a property instead of as a content setting. Using it there, you can use a relative URL, and it will be set at the application level, which is the usual way.
When you use it as a content setting, it's more limited, though possibly inadvertently, and is subject to these restrictions.
I didn't even remember how it worked when I mentioned it as a "content setting" in the assurance page. I'll try and clean the statements up, and I'll probably leave this open until the next release in case I want to adjust how the content setting works to clean it up.
Please try using a relative URL inside the <Errors> element.
> redirectErrors configuration attribute does not handle relative URLs
> --------------------------------------------------------------------
>
> Key: SSPCPP-417
> URL: https://issues.shibboleth.net/jira/browse/SSPCPP-417
> Project: Shibboleth SP - C++
> Issue Type: Bug
> Components: Configuration, Error Handling
> Affects Versions: 2.4.3
> Environment: CentOS 5.7, Shibboleth RPMs 2.4.3-2.2, Apache 2.2.3-53
> Reporter: Terrence G Fleury
> Assignee: Scott Cantor
> Labels: Session
>
> Using documentation found at https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPErrors , I attempted to use the "redirectErrors" attribute with a relative URL. When using an absolute URL such as 'redirectErrors="https://example.org/script.php"', errors were redirected to the 'script.php' handler as expected. When using a relative URL such as 'redirectErrors="script.php"', errors were instead redirected to "https://example.org/Shibboleth.sso/SAML2/POST". I tried several variations such as "/script.php", "../script.php", "/../script.php", etc., but none of them worked. So either the documentation is incorrect (i.e. relative URLs are not allowed), or there is a bug in the code which handles relative URLs.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list