Attributes in SP Session Cookie

Cantor, Scott cantor.2 at osu.edu
Tue Jan 9 20:58:15 EST 2018


On 1/9/18, 3:45 PM, "users on behalf of Sean McHugh" <users-bounces at shibboleth.net on behalf of sean8sean at gmail.com> wrote:

> I have an HTML+JS application that resides on a Shibboleth protected resource.

You can't protect an application like that, security is only possble on the server side. It's the connection from client to server that can be secured, not the client itself.

-- Scott




More information about the users mailing list