idp.cookie.secure Ignored?

Rod Widdowson rdw at steadingsoftware.com
Thu Jun 13 05:29:55 EDT 2019


Scott:

>> Any cookies the IdP sets are governed by it, others are not and would be controlled in whatever way governs them.

> Set-Cookie: JSESSIONID=8D9E91ADF81898B4299A59E6703DE060; Path=/idp; Secure; HttpOnly

The point here is that the IdP doesn’t set JSESSIONID, that’s the container.  Controlling how the container works is outwith IdP configuration so you should use the canonical method...

R



More information about the users mailing list