Question on Sp logout redirect control

Ewing, Bill BEwing at utsystem.edu
Fri Dec 2 14:56:05 EST 2016


I saw in a previous thread that there is a way to control the open redirection of a logout return= url .

"The SP has functionality of this sort, and by default it does end up operating as an open redirector, causing people to complain. Limiting the redirection it allows is a feature you have to enable. " posted by Scott last year

Basically we have an sp that for logout you can put in anything after return=and allow open redirects https://example.com/Shibboleth.sso/Logout?return=anythingunderthesun.com

I haven't been able to find out how to control/limit that behavior to only allow specific redirect urls on logout to avoid emails that we are phishing folks.

Anyone have suggestions or point me to the right place to see examples of how this might be done?

Bill
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161202/4585232b/attachment.html>


More information about the users mailing list