Login target url parameter limit

Pavel Šipoš pavel.sipos at arnes.si
Mon Feb 20 14:52:12 UTC 2023


I understand and I agree.
Just to be clear:

With target set to google.com redirections are:
- 
https://sp.example.com/Shibboleth.sso/Login?target=https%3A%2F%2Fgoogle.com
- 
https://ds.example.com/simplesaml/saml2/sp/idpdisco.php?entityID=https%3A%2F%2Fsp.example.com%2Fsp%2F222222222222&return=https%3A%2F%2Fgoogle.com%2FShibboleth.sso%2FLogin%3FSAMLDS%3D1%26target%3Dhttps%253A%252F%252Fgoogle.com&returnIDParam=entityID&idpentityid=https%3A%2F%2Fidp.example.com%2Fidp%2F12345678
- 
https://google.com/Shibboleth.sso/Login?SAMLDS=1&target=https%3A%2F%2Fgoogle.com&entityID=https%3A%2F%2Fidp.example.com%2Fidp%2F12345678

As you can see the target URL gets set as return URL at request to DS.
--------------------

Without target parameter:
- https://sp.example.com/Shibboleth.sso/Login
- 
https://ds.example.com/simplesaml/saml2/sp/idpdisco.php?entityID=https%3A%2F%2Fsp.example.com%2Fsp%2F222222222222&return=https%3A%2F%2Fsp.example.com%2FShibboleth.sso%2FLogin%3FSAMLDS%3D1%26%26target%3Dhttps%253A%252F%252Fsp.example.com%252F&returnIDParam=entityID&idpentityid=https%3A%2F%2Fidp.example.com%2Fidp%2F12345678
- 
https://sp.example.com/Shibboleth.sso/Login?SAMLDS=1&=&target=https%3A%2F%2Fsp.example.com%2F&entityID=https%3A%2F%2Fidp.example.com%2Fidp%2F12345678
- 
https://idp.example.com/simplesaml/saml2/idp/SSOService.php?SAMLRequest=fZLNboMwEIRfBfkebJx%2FKyDR5NBIaYMC7aGXyoBTLIHtek3avn0hpEp7aC572fE3OyOvgDe1YXHrKnUQ760A5302tQJ2XoSotYppDhKY4o0A5gqWxg87Rn3CjNVOF7pGXgwgrJNarbWCthE2FfYkC%2FF02IWocs4Aw%2Fgky5HrDHxulQAfJE4rmee6Fq7yATTuwRQn%2BzRD3qYTSsV75pUgS%2BNzLq8AkI2pRX8q7gftFThN9xd731QGedtNiF7psZwX83lApou8KEqSE0qnE5JzsTiKYDbrZACt2CpwXLkQUULHI0JHlGTBhI0po8sX5CWXxHdSlVK93a4nH0TA7rMsGQ2xnoWFc6ROgKJVfzQ7G9tftd%2FG8p%2BuUfR%2Fs2Bwl4CQ2bjLMV2u8C%2Bnwdawxw693SS6lsWXF9e1%2FlhbwZ0IUYBwNDz5%2BzWibw%3D%3D&RelayState=https%3A%2F%2Fsp.example.com%2F

--------------------

In SP metadata is set:
<disco:DiscoveryResponse 
Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" 
Location="https://sp.example.com/Shibboleth.sso/Login" index="1"/>

So I would expect DS to redirect user to this disco:DiscoveryResponse 
location and not to the url in target parameter - which as you mentioned 
is expected to be used as last redirecton after SSO has been completed.
Otherwise which url should be used to redirect user after he choosed his 
IdP on DS.

Pavel

On 20/02/2023 15:22, Peter Schober via users wrote:
> * Pavel Šipoš <pavel.sipos at arnes.si> [2023-02-20 15:14]:
>> DS is redirecting user back to the SP with idp entityid set, but it takes
>> that target url as the SP endpoint and not the SP url from metadata.
> Sorry, what "the SP url from metadata"? The target URL will identify a
> resource to send the subject's browser to once SSO has completed,
> e.g. an application- and/or user-specific URL at the SP web server.
> That will never be included in SAML 2.0 Metadata. (There's no element
> for this as it's dynamic by nature.)
>
> -peter

-- 
--
Pavel Sipos, Arnes <pavel.sipos at arnes.si>
ARNES, p.p. 7, SI-1001 Ljubljana, Slovenia
T: +386 1 479 88 00
W: www.arnes.si, aai.arnes.si

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5772 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20230220/8c56c565/attachment.p7s>


More information about the users mailing list