Base64 image in SAML assertion

MikeWho who at me.com
Wed Aug 28 20:20:49 EDT 2013


Thanks Scott, Kevin!


Kevin P. Foote wrote
> But, if you are protecting a login routine at "/your-login-code" and then
> relying on the applications session then I think your request bloat
> would be limited to requests for login..

Aha, I hadn't thought of that. Good idea.

We were considering using that approach for entirely separate reasons (IdP
is sending SessionNotOnOrAfter field, but client wants us to maintain
session beyond that), it hadn't occurred to me that it would also solve this
problem of 'big headers'. 

Many thanks for the ideas!



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Base64-image-in-SAML-assertion-tp7589623p7589630.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list