IdP errors using browser's back button

Cantor, Scott cantor.2 at osu.edu
Thu Oct 10 10:08:42 EDT 2013


On 10/10/13 5:10 AM, "loginmayank" <mayankg at xpanxion.co.in> wrote:
>
>We cannot restrict user to hit back button,if you see google or any other
>application they get the login page with non-editable username.
>
>How the above functionality can be achieved by shibboleth-idp-cas.

It can't, we have no way to implement it that we're aware of. The most
that could be done is to trap the user in the SP by replaying
authentication requests and throwing off login statistics.

Deployments can (and must, if they don't want to look awful) customize the
error page in various ways, and V3 will have an explicit error path for
dealing with the replay or stale request case.

-- Scott




More information about the users mailing list