Question on Login Handlers

Brewer, Edward L lee.brewer at Vanderbilt.Edu
Thu Aug 22 17:24:38 EDT 2013


Dave,

>I think Chris is right on the front side.. your LDAP2 specific app could
>request a special handler. But, the PreviousSession
>handler is where things run into issues and your LDAP2 group will have
>access to stuff they should not.

Well, in the case where a user is disabled in LDAP1 and not in LDAP2... then there should be no previous sessions opened by that user using LDAP1 access.. so they can only have created the session from LDAP2.

Thanks,
Lee
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130822/f25038f8/attachment-0001.html 


More information about the users mailing list