CAS in IdP v3
Marvin Addison
marvin.addison at gmail.com
Thu Feb 4 10:16:52 EST 2016
On Thu, Feb 4, 2016 at 10:08 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
> > The path parameter is appended to every outgoing redirect by the servlet
> > container
>
> Really? I assumed it would only touch redirects to itself, at most.
I assumed the same thing initially, but quickly found otherwise for the
cases I was looking at.
> That's...broken.
I think the lack of flexibility is what's broken. The developer ought to be
able to control the behavior.
> The leakage of the session ID alone makes that a security bug, seems to me.
>
I hadn't thought of that angle. This thread is renewing my energy to push a
little more on that issue. I think discussion of security consequences
might produce more expedient action on their part.
M <users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160204/8d65c062/attachment.html>
More information about the users
mailing list