Problem URL with # on login shibboleth

Cantor, Scott cantor.2 at osu.edu
Wed Jul 29 13:05:05 EDT 2015


On 7/29/15, 11:39 AM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:
>
>> > and what's the relvant relayState setting in your shibboleth2.xml
>> > configuration file?
>> relayState="cookie"
>
>Then you'll have the URL the SP will use for the final redirect (after
>the SAML protocol messages have been exchanged) as part of the HTTP
>Cookie. So is there a difference in those cookies' values?

And just noting, it's the server that populates the cookie's value here, so that still rests on the issue of whether the server could possibly be seeing the fragment, which I believe it cannot.

-- Scott



More information about the users mailing list