embedding IdP's login page (Banner AppNav)

Cantor, Scott cantor.2 at osu.edu
Tue Sep 20 12:13:45 EDT 2016


> This seems like a conceptually bad idea and counter to some of the core
> principles of SSO like maintaining control over the login process... as such, I
> would hazard its common practice for many of us to disallow this by setting
> the X-Frame-Options DENY header?

I have not, I just rely on the fact that third party cookie blocking is now becoming the norm and will naturally break this.

It used to be that I would have to argue that it mattered because "everybody allows them". Apparently, "everybody" is now reaching levels closer to 50% or less, and it seems that my side is winning.

That also means server-side logout is indeed hopeless, BTW. ;-)

-- Scott



More information about the users mailing list