Attempt to spoof header (HTTP_SHIBSESSIONID:) was detected.
Cantor, Scott
cantor.2 at osu.edu
Tue Jul 29 12:23:01 UTC 2025
> I've also brought this up to the Apache tomcat connectors
> devs:
Apache doesn't have the issue really, you can set your own headers as needed based on the server variables the SP sets, that's how it's meant to work.
If they're proxying HTTP to Tomcat, as with Jetty, you have to use headers on that leg, but that doesn't mean you have to set them on the front half to get them there.
-- Scott
More information about the users
mailing list