Chaining Session hooks? (resurrected)
Cantor, Scott
cantor.2 at osu.edu
Tue Jun 6 22:50:30 EDT 2017
On 6/6/17, 10:30 PM, "users on behalf of Jan Vilhuber" <users-bounces at shibboleth.net on behalf of JVilhuber at absolute.com> wrote:
[JV:] Wait, the sessionhook is called AFTER the assertion has been processed, at which point the shib-session is authenticated.
Maybe I'm mis-remembering but the point of the feature was that it allows the session to be aborted before it's completely established. I didn't think it actually relied on the session being in place at that point. But I confess I can't think how it would work otherwise so you're probably correct.
> I DO in fact have the sessionhook locations marked as protected resources, and it WORKS. I can't really see this being a non->protected resources, since session-setup MUST be done after authenticated ONLY. To me being able to access a sessionhook as
> an UNPROTECTED resource would be a security violation.
That really depends on what it's doing, but I wouldn't say you're wrong, it's been years since I looked at that code in any detail.
-- Scott
More information about the users
mailing list