CORS requests against OIDC

Cantor, Scott cantor.2 at osu.edu
Wed May 15 21:30:00 EDT 2019


> It is basically implementing what's described at
> https://wiki.shibboleth.net/confluence/display/IDP30/Cross-
> origin+AJAX+requests+for+Shib-protected+resources
> The SAML endpoints would suffer from the same vulnerable, right?

Yes, and I wouldn't do that either.
 
-- Scott



More information about the users mailing list