is AttributeChecker sessionHook secure?

Scott Cantor scott at restingparrotsoftware.com
Wed Sep 16 13:05:33 UTC 2026



> On Sep 16, 2026, at 8:51 AM, Peter Schober via users <users at shibboleth.net> wrote:
> 
> Well, you can nuke any cookies as part of the sessionHook (e.g. after
> some process determined that access to the protected resource couldn't
> possibly work).

Even there, a malicious client can simply ignore the directive to remove them.

-- Scott



More information about the users mailing list