AW: IdPV3 login page access to AuthnRequest

Roehrl Patrick patrick.roehrl at inet-logistics.com
Tue Jul 28 03:38:36 EDT 2015


Thanks for your reply!
We needed the AssertionConsumerUrl for our password update process. Short description of the process:
1. At the IdP a password update error gets thrown and the user will be redirected with an encrypted one time login token (contains among other things the assertion consumer url) to another web application to update his password
2. user updates his password and then the user gets redirected to the assertion consumer url (which is in our case the same as the webapplication entry point)
3. due to that the user has no session, he gets redirected to the IdP and will be automatically loged in at the IdP (how is not relevant)

Short fact: we used the assertion consumer url to redirect the user to the point where he came from

Patrick

-----Ursprüngliche Nachricht-----
Von: users [mailto:users-bounces at shibboleth.net] Im Auftrag von Cantor, Scott
Gesendet: Montag, 27. Juli 2015 16:11
An: Shib Users
Betreff: Re: IdPV3 login page access to AuthnRequest

On 7/27/15, 6:14 AM, "users on behalf of Roehrl Patrick" <users-bounces at shibboleth.net on behalf of patrick.roehrl at inet-logistics.com> wrote:

>In IdPV2 we used the following lines in the login.jsp to get the AssertionConsumerUrl:

If I knew why, I could probably make a compelling case for why that's a really bad idea and you should be using something else, so I would start with that.

-- Scott

-- 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list