Shib login in pop-up browser window?

David Bantz dabantz at alaska.edu
Wed Oct 15 15:39:43 EDT 2014


Following up, the vendor has corrected their description of what they are doing to state they are issuing the SAML request in an iframe.
I take it the IdP log message 
WARN...No login context available, unable to proceed with authentication
reflects that inability to use cookies in the iframe.  

Thanks to Mike and Scott’s hints that the vendor was using frames, I found an interesting if ultimately inconclusive thread from 2008 which I relayed to the vendor.

Chad La Joie responding to similar errors in 2008 email discussion:
> Yeah, I'm pretty sure this is an issue with IFRAMEs not sending cookies

> like a normal frame would. Scott and I were talking about this the

> other day for other reasons. You'll need to read up on IFRAMEs and how

> your browser handles them.


Scott Cantor in the same 2008 discussion:
> Particularly when SSL is involved. Our experience at OSU, with fairly minimal 

> testing, is that frames are unusable with cookie-based applications when SSL 

> is used (unless all the frames are coming from the same server of course), 

> and we haven't spent much time trying to get around it.


Jim Fox (U Washington) opines:
> A login url in an iframe, even if it did work, is inherently insecure

> and subject to easy attacks. The user has no convient way to

> identify the source of the login page. That's why the login

> is always on a page of its own.


In discussion today, the vendor agreed to replace use of iframe with pop-up window in their next release in about a month’s time.

Thanks all,

David Bantz
U Alaska

 On Oct 14, 2014, at 18:52, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 10/14/14, 10:39 PM, "David Bantz" <dabantz at alaska.edu> wrote:
>> 
>> Going from relayed user report of the time, I see the following line in
>> the IdP logs that reflect this failed attempt:
> 
> Then they're probably not using a pop-up, but a frame.
> 
> -- Scott
> 
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141015/84291696/attachment.html 


More information about the users mailing list