IdP 2.4 Cookie Handling Error
Cantor, Scott
cantor.2 at osu.edu
Thu Jul 17 11:47:34 EDT 2014
On 7/17/14, 11:40 AM, "Paul Hethmon" <paul.hethmon at clareitysecurity.com>
wrote:
>I think in our environment, the empty response sent to the SP just
>resulted in a new AuthnRequest.
I would have thought that would loop. If not, that means the issue isn't
even repeatable.
> So perhaps to the user annoying, but they just logged in again. Now,
>they stop and read the message and make a phone call. I'm thinking of
>adding a js timer to the error page and redirecting after a few seconds
>to a default location. It won't get rid of any problem, but may stop the
>phone calls.
That's what I meant, at least this way you can control the outcome to do
whatever you need (modulo the ugliness of having to test for the error
message, but that's about the only signaling the old design supports).
-- Scott
More information about the users
mailing list