allowPerAttribute=true + all unchecked + 8443 = unintended attribute release
Cantor, Scott
cantor.2 at osu.edu
Mon Jan 29 09:31:15 EST 2018
> Scott addressed this issue. It seems you must either eliminate the
> back channel or populate the attribute assertion on the front channel.
> I would do both.
If the concern is data leakage, that doesn't prevent something trusted from issuing a query. What the SP does or doesn't do implicitly has nothing to do with the security posture of the system.
If you need query support for specific reasons, then simply implement release rules or profile config settings to contrain its use. It's not hard.
-- Scott
More information about the users
mailing list