EXT: Re: Shibboleth IdP - SAMLAuthnConfiguration Proxy - SameSite Cookies

Miles, Ryan rmmiles at kent.edu
Wed Mar 1 16:10:47 UTC 2023


>> I'm guessing because there are no cookies when the third-party IdP POST back?
> It appears that way because without a session, the cookies are new and are accomodated by Chrome's 2 minute rule. Take longer than 2 minutes the first time through and it will break the same way.

ah, I wasn't aware of Chrome's two minute grace period, that makes sense now.


I'm new to Shibboleth IdP, regarding, "The condition hook is present to allow deployers to create scripted or Java-based code to perform User-Agent testing....", would you be able to provide some guidance on how to get the "condition hook" in place for us to write our own conditional user-agent testing? I found the following page referencing different options: https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631700/PredefinedBeans. However, I'm at a loss for which one to use instead of "shibboleth.Conditions.TRUE", where to place the code, available inputs / outputs.


Thanks,
-Ryan


More information about the users mailing list