is AttributeChecker sessionHook secure?
Scott Cantor
scott at restingparrotsoftware.com
Wed Sep 16 13:05:33 UTC 2026
> On Sep 16, 2026, at 8:51 AM, Peter Schober via users <users at shibboleth.net> wrote:
>
> Well, you can nuke any cookies as part of the sessionHook (e.g. after
> some process determined that access to the protected resource couldn't
> possibly work).
Even there, a malicious client can simply ignore the directive to remove them.
-- Scott
More information about the users
mailing list