SPNEGO login flow: Enforce SPNEGO by condition
Cantor, Scott
cantor.2 at osu.edu
Tue Dec 1 12:34:47 EST 2015
On 12/1/15, 12:19 PM, "dev on behalf of Daniel Lutz" <dev-bounces at shibboleth.net on behalf of daniel.lutz at switch.ch> wrote:
>On 2015-12-01 at 17:52, Cantor, Scott wrote:
>> Specifically, check for the missing cookie and set it if the user agent
>> matches in a script auto-run by the password form. The user won't see any
>> difference.
>
>I think there's more to do besides setting the cookie:
>After having set the cookie, the script needs to submit an
>"authn/SPNEGO" event to the flow to make the SPNEGO login flow
>be run as an extended flow.
Yes, but that part is simple.
>Furthermore, the script needs to avoid an endless loop.
Are we currently clearing the cookie or setting it to a zero/false value? That might be a better approach to avoid loops.
-- Scott
More information about the dev
mailing list