CAS Service URL issue?

Dan Oachs doachs at gac.edu
Wed Jun 7 12:20:45 EDT 2017


What about the question where it looks like a double slash is being 
added to the url?

 > Double slash example
 >
 > Initial request:
 > 
https://sso.gac.edu/idp/profile/cas/login?service=https%3A%2F%2Fbeta.gac.edu%2F%2Fregistrar%2Ffinals.php
 >
 > Redirects back to:
 > 
https://beta.gac.edu/registrar/finals.php?ticket=ST-1494947652754-6ygj50tiVewAVcV6R1IWo4YrI
 >
 > Log file has:
 > 
idp-audit.log:20170516T151412Z|||https://beta.gac.edu//registrar/finals.php|https://www.apereo.org/cas/protocol/login||||testuser|||testuser|ST-1494947652754-6ygj50tiVewAVcV6R1IWo4YrI||2620:46:8000:64:e23f:49ff:feac:5047|
 > 
idp-audit.log:20170516T151412Z|||https://beta.gac.edu/registrar/finals.php|https://www.apereo.org/cas/protocol/serviceValidate||||||||ST-1494947652754-6ygj50tiVewAVcV6R1IWo4YrI||2620:46:8000:128::16|
 > idp-process.log:2017-05-16 10:14:12,755 - INFO
 > [net.shibboleth.idp.cas.flow.impl.GrantServiceTicketAction:123] -
 > Granted service ticket forhttps://beta.gac.edu//registrar/finals.php
 > 2620:46:8000:64:e23f:49ff:feac:5047
 > idp-process.log:2017-05-16 10:14:12,756 - INFO
 > [Shibboleth-Audit.SSO:241] -
 > 
20170516T151412Z|||https://beta.gac.edu//registrar/finals.php|https://www.apereo.org/cas/protocol/login||||testuser|||testuser|ST-1494947652754-6ygj50tiVewAVcV6R1IWo4YrI| 

 > 2620:46:8000:64:e23f:49ff:feac:5047
 > idp-process.log:2017-05-16 10:14:12,796 - INFO
 > [Shibboleth-Audit.SSO:241] -
 > 
20170516T151412Z|||https://beta.gac.edu/registrar/finals.php|https://www.apereo.org/cas/protocol/serviceValidate||||||||ST-1494947652754-6ygj50tiVewAVcV6R1IWo4YrI| 

 > 2620:46:8000:128::16


Thanks,

      Dan Oachs

      Gustavus Adolphus College


On 06/06/2017 08:31 PM, Cantor, Scott wrote:
> On 6/5/17, 3:43 PM, "users on behalf of Dan Oachs" <users-bounces at shibboleth.net on behalf of doachs at gac.edu> wrote:
>
>>   Is there a configuration setting that needs to be adjusted? Or is this a bug?
> The service parameter has to be URL-encoded. If the URL utself contains a query string or unusual characters in its own right, then those special characters have to be encoded, essentially showing up as doubly-encoded in the parameter on the IdP side.
>
> In this case, the plus would have to encoded into percent/hex syntax itself.
>
> -- Scott
>
>
>


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3984 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20170607/4726b580/attachment.p7s>


More information about the users mailing list