embedding IdP's login page (Banner AppNav)
Cantor, Scott
cantor.2 at osu.edu
Tue Sep 20 12:13:45 EDT 2016
> This seems like a conceptually bad idea and counter to some of the core
> principles of SSO like maintaining control over the login process... as such, I
> would hazard its common practice for many of us to disallow this by setting
> the X-Frame-Options DENY header?
I have not, I just rely on the fact that third party cookie blocking is now becoming the norm and will naturally break this.
It used to be that I would have to argue that it mattered because "everybody allows them". Apparently, "everybody" is now reaching levels closer to 50% or less, and it seems that my side is winning.
That also means server-side logout is indeed hopeless, BTW. ;-)
-- Scott
More information about the users
mailing list