idp.cookie.secure Ignored?
Rod Widdowson
rdw at steadingsoftware.com
Thu Jun 13 05:29:55 EDT 2019
Scott:
>> Any cookies the IdP sets are governed by it, others are not and would be controlled in whatever way governs them.
> Set-Cookie: JSESSIONID=8D9E91ADF81898B4299A59E6703DE060; Path=/idp; Secure; HttpOnly
The point here is that the IdP doesn’t set JSESSIONID, that’s the container. Controlling how the container works is outwith IdP configuration so you should use the canonical method...
R
More information about the users
mailing list