Tue Oct 22 09:40:35 EDT 2019

No HTMLLocal storage for the IdP, just client-side cookies. And yes to enforcing client address consistency. So, with that said, does the IdP check anything beyond the contents of the cookie for session validity?


That depends on whether HTML storage is enabled, not to mention that the IdP enforces address restrictions. I consider it a security vulnerability in Jetty and Tomcat that they don't.
