RemoteUser authnMethodHeader example?

Cantor, Scott cantor.2 at osu.edu
Tue Feb 7 09:46:03 EST 2017


> Couldn't someone insert an illicit header on the browser side?

If you don't use a header that your external method adequately controls. If you don't configure a header to check, it doesn't look. It's there for people with systems capable of safely utilizing it, often involving proxying where you might have tight controls over things.

-- Scott



More information about the users mailing list