donotcache and forceAuthn

Jeffrey Crawford jeffreyc at ucsc.edu
Mon Aug 21 15:45:40 EDT 2017


We've actually been relying on the current behavior for better or worse. If
someone at the beginning of the day selects to cache, and a forceauthn page
is used in between even if the box shows ticked it just logs them in to the
next non-forceauthn page. We did this because we wanted to the default to
be donotcache for new logins, but not existing ones.

If this is fixed is there an easy way in the login.vm page to "remember"
the checkbox state during the SSO session? (I'm not a web developer :) )

Jeffrey E. Crawford
Enterprise Service Team <jeffreyc at ucsc.edu>
    ^         ^
   / \  ^    / \    ^
  /   \/ \  /   \  / \
 /        \/     \/   \
/                      \

You have been assigned this mountain to prove to others that it *can* be
moved.

On Fri, Aug 18, 2017 at 6:13 AM, Manuel Haim <haim at hrz.uni-marburg.de>
wrote:

> On 15.08.2015 01:24, Cantor, Scott wrote:
> > On 8/14/15, 7:01 PM, "users on behalf of Jeffrey Crawford" <
> users-bounces at shibboleth.net on behalf of jeffreyc at ucsc.edu> wrote:
> >
> >> Okay sorry I reread you response, Basically all I'm asking is that if
> an SP requests forceAuthn we have a way to see that in the login.vm
> template, that way we can remove the checkbox to set
> >> donotcache since it's an irrelevant option for a forceAuthen service
> >
> > Except it's *not* irrelevant. You do have a way, but that wouldn't make
> sense. The caching option affects what happens on the *next* request, not
> the one you're processing at the time ForceAuthn would be present.
> >
> > -- Scott
> >
>
> Hi,
>
> in IdP 3.3.1, it seems you can only change behaviour from "donotcache"
> to "cache", but not the other way round.
>
> Just filed a bug:
> https://issues.shibboleth.net/jira/browse/IDP-1207
>
> -Manuel
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170821/6a6a00cb/attachment.html>


More information about the users mailing list