Lazy sessions and authorization (Drupal)

Cantor, Scott cantor.2 at osu.edu
Fri Oct 25 10:18:57 EDT 2013


On 10/25/13, 10:10 AM, "Laas Toom" <Laas.Toom at ut.ee> wrote:

>On 25.10.2013, at 15:36, Peter Schober <peter.schober at univie.ac.at> wrote:
>
>> * Laas Toom <Laas.Toom at ut.ee> [2013-10-25 14:17]:
>>> Is there a way to apply authorization when using lazy sessions?
>> 
>> Not with httpd directives, no.
>
>But with Shibboleth XML directives this is possible? Could you point me
>to docs or something?

In theory I suppose one could combine rules and negate a rule requiring a
session or something. I don't think it's ever been done.

>I will try that too, but the documentation also requires me to enable
>ShibUseHeaders which made me a bit wary of their advice and hoped
>somebody here has some experience.

If their code is reading headers only (which would be a bad thing), then
that advice is certainly necessary.

-- Scott




More information about the users mailing list