PostAuthenticationFlows for non-SAML profiles

Cantor, Scott cantor.2 at osu.edu
Fri Aug 21 10:42:11 EDT 2015


On 8/21/15, 10:30 AM, "dev on behalf of David Langenberg" <dev-bounces at shibboleth.net on behalf of davel at uchicago.edu> wrote:
>
>The redirect_url (while provided by the user-agent) is validated against OIDC metadata just like a SAML ACS URL.  It's something you can trust.

Yes, but we don't use the SAML endpoint as part of the UI information, we use other information. More to the point though, it isn't that OIDC doesn't have metadata, it's how it's acquired and who's asserting it that I fundamentally don't accept displaying information from, at least in an unqualified way (and when it comes to actual web content, sort of at all really).

That ties into the last point in the original message about being able to describe to the user how the site is being authenticated.

-- Scott



More information about the dev mailing list