MPASSid-proxy OAuth (Facebook) and OIDC (Google) IdP AuthN Integration

Cantor, Scott cantor.2 at osu.edu
Tue Nov 27 09:27:36 EST 2018


On 11/27/18, 4:56 AM, "dev on behalf of Philip Smart" <dev-bounces at shibboleth.net on behalf of Philip.Smart at jisc.ac.uk> wrote:

> Yes, I can see you have a valid use case without requiring the session layer, that makes sense. I was just looking at it
> from the perspective of a more standard Shib AuthN implementation - which as you say, was not its exact purpose. 

There are some good reasons for proxying without sessions in the IdP (clarity around timeouts and such is a big one), I would generally say that the only great reason to ever not do it that way would be logout.

-- Scott




More information about the dev mailing list