Expired session not posting saml after idp redirect
Peter Schober
peter.schober at univie.ac.at
Wed Oct 17 06:31:32 EDT 2018
* JamesP <jcparsons at gmail.com> [2018-10-17 07:50]:
> Peter Schober wrote
> > If the SP sends a SAML 2.0 authentication request to the IDP and the
> > IDP literally replies with a redirect to the SP's resource then the
> > IDP would be broken: An IDP only deals with SAML protocol messages, as
> > far as any SP is concerned. In reply to an authn request it would only
> > send a SAML response to the requested (or defaulted) Assertion
> > Consumer Service URL of the SP. It's the SP that would make any final
> > redirects to the resource.
>
> IDP is SecureAuth. I'm thinking I might need to switch this to passive
> session and have the application force session timeout and re-login as
> required.
>
> web trace shows CORS errors... multiple redirect loops.
Well, did you establish that the IDP sent the browser directly to the
protected resource instead of the SP's ACS URLs or not?
-peter
More information about the users
mailing list