PostAuthenticationFlows for non-SAML profiles

David Langenberg davel at uchicago.edu
Fri Aug 21 10:30:27 EDT 2015


> On Aug 21, 2015, at 8:27 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
> On 8/21/15, 10:20 AM, "dev on behalf of David Langenberg" <dev-bounces at shibboleth.net on behalf of davel at uchicago.edu> wrote:
>> 
>>> 
>>> OTOH, showing maybe just the virtual host might be sensible.
>> 
>> I still cringe at this (mypersonalapp://process-oauth-response)
> 
> Certainly in SAML terms, yes, we use the UI metadata as the abstraction for this, and the entityID in the worst case.
> 
> I don't believe it's appropriate to display any of that sort of information if acquired from an untrusted source (and the site itself can't be trusted).

The redirect_url (while provided by the user-agent) is validated against OIDC metadata just like a SAML ACS URL.  It's something you can trust.

Dave



More information about the dev mailing list