Basic Authentication on Password flow

Marco Naimoli marco.naimoli at unipd.it
Wed Dec 14 08:56:40 EST 2016


Il 14/12/2016 14:18, users-request at shibboleth.net ha scritto:
> On 12/14/16, 4:29 AM, "users on behalf of Marco Naimoli"
> <users-bounces at shibboleth.net on behalf of marco.naimoli at unipd.it> wrote:
>> > What is the correct and simpler way to disable this feature (hope it's not creating a new flow) ?
> There is no supported way. You can file a RFE for that, it would just take a fairly simple patch and you would be able to apply that ahead of time in a manner that would survive upgrades in the future since it would match the change made to the code.
>
> I'd be curious why you care about this though.
>
> -- Scott

I'd like to control to switch on or off this feature; I have this need
because we have a test IDP installation, protected by a basic auth:
users that wants

to use it must authenticate with a personal password. Then they can do
their tests using test users with test passwords; in a standard IDP
installation

users receive an error about a failed authentication, due to the check
of the basic auth data. It's an aesthetic problem, I could solve it
modifying views,

probably, but I don't want also that anyone can authenticate "outside"
the IDP, to avoid that a site/webapp can be used to collect user passwords

In the future I could choose to enable this feature, for some directly
controlled SP: that's why I was looking a simple way (like changing a
parameter)

to switch the feature on or off

Thank you very much

Marco

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161214/7b6353d2/attachment.html>


More information about the users mailing list