<div dir="ltr">Hi everyone, I'm Andres de los Reyes and I work at the University of Cuenca, Ecuador, we are securing our sites with sibboleth and now I've found some issues that I really don't know how to deal with.<div><br></div><div>We have 2 java web apps: <a href="http://app1.example.com">app1.example.com</a> and <a href="http://app2.example.com">app2.example.com</a>, both secure with shibboleth, app1 carries the UI (Angular 2) and some minor web services, and app2 has most of the business logic with rest web services developed in JAVA.</div><div><br></div><div>So here is the deal, the user access app1, since there is no sessions it gets redirected to the login page, once this is done the redirection will open <a href="http://app1.example.com">app1.example.com</a>. Now when the user wants to save some data, angular 2 will call a web service in <a href="http://app2.example.edu">app2.example.edu</a>, here is the issue: Since the user has only logged in to app1 there will be no cookie present for app2, this triggers a redirect that the call can't handle. The other possibility is that Angular 2 will call a web service in app1, which in turn will call a web service in app2. Can you pleas tell me if this is possible, and if so how can this be done?</div><div><br></div><div>Thanks in advance</div><div><br></div><div>Andres</div></div>
<br>
<div><font face="Arial, Helvetica, sans-serif"><span style="font-size:13px">Advertencia legal: </span></font></div><div><font face="Arial, Helvetica, sans-serif"><span style="font-size:13px">Este mensaje y, en su caso, los archivos anexos son confidenciales, especialmente en lo que respecta a los datos personales, y se dirigen exclusivamente al destinatario referenciado. Si usted no lo es y lo ha recibido por error o tiene conocimiento del mismo por cualquier motivo, le rogamos que nos lo comunique por este medio y proceda a destruirlo o borrarlo, y que en todo caso se abstenga de utilizar, reproducir, alterar, archivar o comunicar a terceros el presente mensaje y ficheros anexos, todo ello bajo pena de incurrir en responsabilidades legales. Las opiniones contenidas en este mensaje y en los archivos adjuntos, pertenecen exclusivamente a su remitente y no representan la opinión de la Universidad de Cuenca salvo que se diga expresamente y el remitente esté autorizado para ello. El emisor no garantiza la integridad, rapidez o seguridad del presente correo, ni se responsabiliza de posibles perjuicios derivados de la captura, incorporaciones de virus o cualesquiera otras manipulaciones efectuadas por terceros.</span></font></div>