Login target url parameter limit

Pavel Šipoš pavel.sipos at arnes.si
Mon Feb 20 13:27:35 UTC 2023


Oh, I see.
I can confirm that with entityid set the redirection is blocked on SP side.

It is actually our DS that is making redirection and not shibboleth SP 
(I checked that now with samltracer).
As we use simplesamlphp for DS I will have to look for answer there.

Thank you for your explanation.

Pavel

On 20/02/2023 14:09, Peter Schober via users wrote:
> * Pavel Šipoš <pavel.sipos at arnes.si> [2023-02-20 11:51]:
>> We have set redirectLimit on Sessions element and its working for return url
>> on logout but not on target parameter when logging in ( for example:
>> /Shibboleth.sso/Login?target=https://google.com )
> What exactly happens when you access an URL like that? Does the SP
> actually redirect to the requested target URL?
> Without an entityID present on that URL I'm guessing the SP will
> forward the browser to a configured SAMLDS. If so the request could
> fail at the SAMLDS[1] or would otherwise fail back at the SP once the
> selected IDP is known.
> -peter
>
> [1] E.g. the SWITCHwayf software will fail with an error:
> "The return URL ... could not be verified for Service Provider $SPentityID"
> when configured appropriately,
> cf. https://gitlab.switch.ch/aai/SWITCHwayf/-/blob/master/etc/config.dist.php#L112-119

-- 
--
Pavel Sipos, Arnes <pavel.sipos at arnes.si>
ARNES, p.p. 7, SI-1001 Ljubljana, Slovenia
T: +386 1 479 88 00
W: www.arnes.si, aai.arnes.si

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5772 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20230220/54746c30/attachment.p7s>


More information about the users mailing list