Testing idp.shibboleth.net snapshot
Ian Young
ian at iay.org.uk
Mon Mar 9 11:32:41 EDT 2015
> On 8 Mar 2015, at 17:23, Tom Zeller <tzeller at dragonacea.biz> wrote:
>
> The latest IdPv3 snapshot is ready for testing, to test consent expiry
> using a browser :
>
> (1) remove shib_idp_persistent_ss cookie
> (2) SSO
> (3) accept the default attribute release consent "Ask me again if
> information changes" option or select "Do not ask me again"
> (4) wait at least 24h
> (5) repeat step (2) SSO to same SP(s)
>
> If you're prompted for attribute release consent again, I've done
> something wrong, let me know.
I updated my IdP on Sunday and logged in to the Shib wiki. I've done that again today and was not reprompted, so it seems to be OK.
My logs do show one of those "Unwrapped data has expired" messages, which I think you were expecting not to happen now. On the other hand, perhaps *this* instance of that message is talking about the IdP session cookie (which I assume also uses the data sealer), and not the consent cookie. Does that sound right?
> P.S. A Selenium test for this kind of thing might be possible, not
> sure at the moment
I'd guess lying to the code about what time it is would be the tricky part. Is that something Selenium has built in?
-- Ian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20150309/16ea4dea/attachment-0001.bin
More information about the dev
mailing list