PostAuthenticationFlows for non-SAML profiles

Cantor, Scott cantor.2 at osu.edu
Fri Aug 21 10:27:15 EDT 2015


On 8/21/15, 10:20 AM, "dev on behalf of David Langenberg" <dev-bounces at shibboleth.net on behalf of davel at uchicago.edu> wrote:
>
>> 
>> OTOH, showing maybe just the virtual host might be sensible.
>
>I still cringe at this (mypersonalapp://process-oauth-response)

Certainly in SAML terms, yes, we use the UI metadata as the abstraction for this, and the entityID in the worst case.

I don't believe it's appropriate to display any of that sort of information if acquired from an untrusted source (and the site itself can't be trusted).

The virtual host is at least "true" in the sense that for a redirect-driven protocol, obviously that's exactly what the IdP's going to send you to, but I don't disagree that it's potentially confusing.

-- Scott



More information about the dev mailing list