Chaining Session hooks? (resurrected)

Cantor, Scott cantor.2 at osu.edu
Tue Jun 6 22:50:30 EDT 2017


On 6/6/17, 10:30 PM, "users on behalf of Jan Vilhuber" <users-bounces at shibboleth.net on behalf of JVilhuber at absolute.com> wrote:

 [JV:] Wait, the sessionhook is called AFTER the assertion has been processed, at which point the shib-session is authenticated.

Maybe I'm mis-remembering but the point of the feature was that it allows the session to be aborted before it's completely established. I didn't think it actually relied on the session being in place at that point. But I confess I can't think how it would work otherwise so you're probably correct.

> I DO in fact have the sessionhook locations marked as protected resources, and it WORKS. I can't really see this being a non->protected resources, since session-setup MUST be done after authenticated ONLY. To me being able to access a sessionhook as
> an UNPROTECTED resource would be a security violation.

That really depends on what it's doing, but I wouldn't say you're wrong, it's been years since I looked at that code in any detail.

-- Scott




More information about the users mailing list