CAS in IdP v3

Marvin Addison marvin.addison at gmail.com
Thu Feb 4 10:16:52 EST 2016


On Thu, Feb 4, 2016 at 10:08 AM Cantor, Scott <cantor.2 at osu.edu> wrote:

> > The path parameter is appended to every outgoing redirect by the servlet
> > container
>
> Really? I assumed it would only touch redirects to itself, at most.


I assumed the same thing initially, but quickly found otherwise for the
cases I was looking at.


> That's...broken.


I think the lack of flexibility is what's broken. The developer ought to be
able to control the behavior.


> The leakage of the session ID alone makes that a security bug, seems to me.
>

I hadn't thought of that angle. This thread is renewing my energy to push a
little more on that issue. I think discussion of security consequences
might produce more expedient action on their part.

M <users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160204/8d65c062/attachment.html>


More information about the users mailing list