audit log entry for null CAS service
Cantor, Scott
cantor.2 at osu.edu
Tue Nov 14 09:56:08 EST 2017
> When a client requests the CAS login page without providing a service, the
> IDP returns an error page "An error occurred: ServiceNotSpecified" and
> HTTP code 500. However, it also logs that in the audit log.
The audit log is supposed to be written to as much as possible in response to any query. In the SAML case, we certainly try and log errors unless told otherwise. Of course the default format remains completely useless. I think we settled on dumping the V2 compatibility and just shipping a reasonable default in 3.4, though we ordinarily wouldn't do that before 4.0.
-- Scott
More information about the users
mailing list