Modify forceAuthn Authentication Engine Behavior
Cantor, Scott
cantor.2 at osu.edu
Fri Dec 16 00:27:26 GMT 2011
On 12/16/11 12:50 AM, "Chad La Joie" <lajoie at itumi.biz> wrote:
>
>But again, the only actual solution is to either require
>authentication for every single request or educate the user so they
>don't do dumb things.
That would be true if there was anything the user could do to actually
terminate the IdP session, but that isn't generally feasible with modern
browsers and the typical kiosk.
I don't think forceAuthn is implemented incorrectly, and I would say that
the AuthnContext solution is probably the right one. But that only works
if you can react to the error at the IdP that blocks principal switching
with some user action, and I can't think what that would be at the moment.
-- Scott
More information about the dev
mailing list