PostAuthenticationFlows for non-SAML profiles
David Langenberg
davel at uchicago.edu
Fri Aug 21 10:30:27 EDT 2015
> On Aug 21, 2015, at 8:27 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> On 8/21/15, 10:20 AM, "dev on behalf of David Langenberg" <dev-bounces at shibboleth.net on behalf of davel at uchicago.edu> wrote:
>>
>>>
>>> OTOH, showing maybe just the virtual host might be sensible.
>>
>> I still cringe at this (mypersonalapp://process-oauth-response)
>
> Certainly in SAML terms, yes, we use the UI metadata as the abstraction for this, and the entityID in the worst case.
>
> I don't believe it's appropriate to display any of that sort of information if acquired from an untrusted source (and the site itself can't be trusted).
The redirect_url (while provided by the user-agent) is validated against OIDC metadata just like a SAML ACS URL. It's something you can trust.
Dave
More information about the dev
mailing list