idp RemoteUser url-parameters jsession occasional-login-failures

Jim Fox fox at washington.edu
Fri Oct 7 13:59:04 EDT 2016



>> and that's OK, but some clients (I think it's the clients) gratuitously add that
>> parameter to the next redirect
>
> It's the server. Standard container behavior when creating the Java session is to drop a cookie and include the value in the redirect URL, and once the cookie comes back, it detects that and knows not to continue adding the parameter.
>

I'm thinking client because it's an occasional thing.  Most requests do not come in with the jsession parameter; and those that do do not usually add it to the redirects.
When we get the parameter on the initial idp access only about 6% of the time do we see the it appended to the authn step.

Jim


More information about the users mailing list