Login target url parameter limit

Peter Schober peter.schober at univie.ac.at
Mon Feb 20 14:22:15 UTC 2023


* Pavel Šipoš <pavel.sipos at arnes.si> [2023-02-20 15:14]:
> DS is redirecting user back to the SP with idp entityid set, but it takes
> that target url as the SP endpoint and not the SP url from metadata.

Sorry, what "the SP url from metadata"? The target URL will identify a
resource to send the subject's browser to once SSO has completed,
e.g. an application- and/or user-specific URL at the SP web server.
That will never be included in SAML 2.0 Metadata. (There's no element
for this as it's dynamic by nature.)

-peter


More information about the users mailing list