Stupid CAS Saml11TicketValidator Parsing Issue

Marvin Addison marvin.addison at gmail.com
Thu Nov 12 13:33:18 EST 2015


>
> We consciously don't expose XML namespace prefixes as a directly
> configurable option in the library, because code (like the stuff in
> question here) that can't deal with with arbitrary prefixes is just broken
>

Wholeheartedly agree. I really do feel bad for even considering a
server-side fix for a broken client, but I'm trying to be practical.

But regarding this, just curious:  I thought this was fixed in newer
> versions of the CAS client, and the workaround was just dropping in a newer
> version of the CAS client jar.
>

That's correct.


> and the workaround was just dropping in a newer version of the CAS client
> jar.
>

Unfortunately we have so many apps that are affected that it is rapidly
approaching not feasible, thus investigating work involved in a server-side
fix.

M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20151112/a3c9c3ad/attachment.html>


More information about the dev mailing list