Shibboleth SP: Data loss when a POST triggers a redirect to re-authenticate
Tom Noonan
tom at joinroot.com
Fri Feb 8 09:44:07 EST 2019
Good morning:
We're experiencing a pain point with the SP and I wanted to see if there is
some advice on how to mitigate it. We're using the Shibboleth SP with
Apache as a transparent authenticating proxy in front of our app, and our
app which allows data entry via HTTP POST requests. We're seeing issues
where the user submits data via a HTTP post, but their session with the SP
has expired so the SP redirects to the IdP to re-authenticate. When the
reauthentication happens the POST data is lost. We do have our session
timeout values turned up but that is only reducing the probability of this
error, not fully preventing against it.
My understanding is that this is a protocol level problem, and that it
isn't possible to maintain the POST data through the redirect. Is that
correct? Are there any quick wins to defend against this we can
implement?
--Tom Noonan II
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190208/aaa50c2e/attachment.html>
More information about the users
mailing list