PostAuthenticationFlows for non-SAML profiles
Cantor, Scott
cantor.2 at osu.edu
Fri Aug 21 10:42:11 EDT 2015
On 8/21/15, 10:30 AM, "dev on behalf of David Langenberg" <dev-bounces at shibboleth.net on behalf of davel at uchicago.edu> wrote:
>
>The redirect_url (while provided by the user-agent) is validated against OIDC metadata just like a SAML ACS URL. It's something you can trust.
Yes, but we don't use the SAML endpoint as part of the UI information, we use other information. More to the point though, it isn't that OIDC doesn't have metadata, it's how it's acquired and who's asserting it that I fundamentally don't accept displaying information from, at least in an unqualified way (and when it comes to actual web content, sort of at all really).
That ties into the last point in the original message about being able to describe to the user how the site is being authenticated.
-- Scott
More information about the dev
mailing list