Attribute checking based on sp location
Peter Schober
peter.schober at univie.ac.at
Sun Oct 16 10:44:47 EDT 2016
* SAMUELE RILLI <samuele.rilli at unicam.it> [2016-10-14 19:02]:
> This scenario is tricking me: a user logs in as a non-admin account
> to /account, then if he moves to /admin a 403 Forbidden error is
> generated (as expected). In the latter case I need to remove the sp
> session and trigger a new authentication for /account which will
> allow the user to access the resource...
Not without changing identity at the IDP (or picking another IDP), so
as Scott said, logout and/or user-switching at the IDP would need to
be involved.
-peter
More information about the users
mailing list