Cross Origin requests for Shibboleth IDP v4.2
prasanna cg
prasannacgin at yahoo.in
Mon Aug 29 12:26:29 UTC 2022
Hello Experts,
I have a Salesforce application (protected by Shibboleth IDP v4.2.1). A specific business flow requires invocation of another SAML SSO protected application (by the same Shib IDP) in an iframe. The error thrown in the iframe is the “Stale Request Error”. I understood this to be a possible CORS issue as accessing the second application in a new browser tab (with active IDP session) goes through SAML SSO seamlessly without any issue.
Is my understanding of the issue correct ? If yes, what is the suggested workaround to frame an IDP protected site ? I came across the article here and I would like to understand if this workaround is still valid for IDP v4.2.1 as I see the article was last updated by 2020. Also, my Shib IDP is deployed in Tomcat 9. Do we have equivalent steps for Tomcat ?
Please share your recommendations.
Thanks,
Prasanna
More information about the users
mailing list