Session/Cookie Question

Check mrcheck at gmail.com
Thu Jan 2 18:16:22 UTC 2025


That may be enough.  The user's browser heads to
https://mySP.com/pageTheyWantToGoTo.  They get redirected to something like
https://idp.com/warning.vm.  When they click a button on that page in their
browser, the browser sends them back to the IDP which then sends them to
https://mySP.com/pageTheyWantToGoTo.  Same thing happens with the Terms of
Use one.  How does it know where the user was heading to?  Is it in a
session variable?  A cookie?  It ends up taking them there so it's gotta
know where they were headed. Or does it just know https://mySP.com and
doesn't save the whole address of https://mySP.com/pageTheyWantToGoTo?

On Thu, Jan 2, 2025 at 1:08 PM Cantor, Scott <cantor.2 at osu.edu> wrote:

> > I need the warning intercept view to know where the user
> > was heading to when they got intercepted.
>
> If by "where" you mean something regarding the SP, there is no support in
> SAML (or OpenID) for knowing that information beyond the level of which SP
> it was (the entityID). By design the IdP isn't meant to know any more
> detail than that.
>
> -- Scott
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250102/bd7a1c98/attachment.htm>


More information about the users mailing list