Session/Cookie Question
Check
mrcheck at gmail.com
Thu Jan 2 18:16:22 UTC 2025
That may be enough. The user's browser heads to
https://mySP.com/pageTheyWantToGoTo. They get redirected to something like
https://idp.com/warning.vm. When they click a button on that page in their
browser, the browser sends them back to the IDP which then sends them to
https://mySP.com/pageTheyWantToGoTo. Same thing happens with the Terms of
Use one. How does it know where the user was heading to? Is it in a
session variable? A cookie? It ends up taking them there so it's gotta
know where they were headed. Or does it just know https://mySP.com and
doesn't save the whole address of https://mySP.com/pageTheyWantToGoTo?
On Thu, Jan 2, 2025 at 1:08 PM Cantor, Scott <cantor.2 at osu.edu> wrote:
> > I need the warning intercept view to know where the user
> > was heading to when they got intercepted.
>
> If by "where" you mean something regarding the SP, there is no support in
> SAML (or OpenID) for knowing that information beyond the level of which SP
> it was (the entityID). By design the IdP isn't meant to know any more
> detail than that.
>
> -- Scott
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250102/bd7a1c98/attachment.htm>
More information about the users
mailing list