On 8/20/13 12:05 PM, "Ulrich Lorenz PH Luzern" <lorenz.ulrich at phlu.ch> wrote: >But in the $_SERVER global variable, there are no traces of a valid >Shibboleth session apart from the cookie: PHP isn't my area, but that generally means you aren't protecting whatever URL is being accessed there. -- Scott