Wordpress & Shibboleth Headers

Cantor, Scott cantor.2 at osu.edu
Wed May 11 13:41:09 EDT 2016

> The Wordpress Shibboleth plugin says just add
> AuthType shibboleth
> Require shibboleth
> for lazy session.  I ended up adding a second instance so I added the
> ShibRequestSetting applicationId wordpress
> It seemed that without both
> ShibRequireSession Off
> ShibUseHeaders On
> I was still looping.

Well, I can't say if you need headers, and you certainly shouldn't use them in general. If the plugin needs headers then it needs to document that it does, but it shouldn't need them in general, so that would be a bug.

Setting the other value off simply isn't going to do anything. If it does, you have other settings in other places overriding the default value, and that matters a great deal. That's just a time bomb waiting to go off.

-- Scott

