<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
Hi All,
<div class=""><br class="">
</div>
<div style="orphans: 2; widows: 2;" class=""><font face=".SF NS Text" class="">I have put together three options for<span style="orphans: 2; widows: 2; background-color: rgb(255, 255, 255);" class=""> integrating a synchroniser token pattern based Cross Site
 Request Forgery (CSRF) defence into the IdP's Password authentication flow [1] (and potentially more widely). Each comes with an implementation (in a feature branch) on my personal git repository [2]</span></font> (which should allow anonymous read access). </div>
<div style="orphans: 2; widows: 2;" class=""><br class="">
</div>
<div style="orphans: 2; widows: 2;" class="">Login CSRF is fairly difficult to exploit on the IdP in its current state, but an additional defence should make that more robust/concrete. </div>
<div style="orphans: 2; widows: 2;" class=""><br class="">
</div>
<div style="orphans: 2; widows: 2;" class="">This work does not represent production ready enhancements, or is not endorsed by anybody at this stage. It just represents some investigatory work and proof of concepts I have been working on. </div>
<div style="orphans: 2; widows: 2;" class=""><br class="">
</div>
<div style="orphans: 2; widows: 2;" class="">All comments welcome…including, why did you do that, why did you not just do this….</div>
<div class="">
<div style="orphans: 2; widows: 2;" class=""><span style="background-color: rgb(255, 255, 255);" class=""><br class="">
</span></div>
<div style="orphans: 2; widows: 2;" class=""><span style="background-color: rgb(255, 255, 255);" class=""><br class="">
</span></div>
<div style="orphans: 2; widows: 2;" class=""><span style="background-color: rgb(255, 255, 255);" class=""><br class="">
</span></div>
<div style="orphans: 2; widows: 2;" class=""><span style="background-color: rgb(255, 255, 255);" class="">[1] </span><a href="https://wiki.shibboleth.net/confluence/display/DEV/CSRF+Mitigation+Options" class="">https://wiki.shibboleth.net/confluence/display/DEV/CSRF+Mitigation+Options<br class="">
</a>[2] <a href="mailto:git@git.shibboleth.net" class="">git@git.shibboleth.net</a>:philsmart/java-identity-provider</div>
</div>
<div class=""><br class="">
</div>
<div class="">Phil</div>


<font size="1"> <font face="Corbel">   <br />
Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under Company No. 5747339, VAT No. GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill, Bristol, BS2 0JA. T 0203 697 5800.<br /><br />
 
Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 2881024, VAT number GB 197 0632 86. The registered office is: One Castle Park, Tower Hill, Bristol BS2 0JA. T 0203 697 5800.
 
    
</font></font></body></html>