idp.authn.identitySwitchIsError

Ullfig, Roberto Alfredo rullfig at uic.edu
Mon Apr 26 14:15:44 UTC 2021


I started coding for MFA years ago under 3.x and recently migrated that code to 4.1. I noticed this setting in my old code:

idp.authn.identitySwitchIsError = true

docs say:

"Whether to fail requests if a user identity after authentication doesn't match the identity in a pre-existing session"

This defaults to false in 4.1. Should this be true - what exactly does it do? Seems like it should always be true.

---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210426/a38f4b48/attachment.htm>


More information about the users mailing list