<div dir="ltr"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span style="font-size:small;text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">How can I route to a server api that is in charge of instantiating a jwt token? Plus I have one more requirement, developers need to be able to access application without going through Shibboleth. Please pardon my ignorance in this framework.</span></blockquote><div><br></div><div>The simplest solution is likely to make your Shibboleth-protected landing "page" generate the JWT -- whatever it needs to do to generate it -- and deliver it with the application.</div><div><br></div><div>Greg</div></div><br><div class="gmail_quote"><div dir="ltr">On Fri, Jul 6, 2018 at 11:32 AM Starkey, Don [BSD] - CRI <<a href="mailto:dstarkey@bsd.uchicago.edu">dstarkey@bsd.uchicago.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hello,<br>
<br>
How can I route to a server api that is in charge of instantiating a jwt token? Plus I have one more requirement, developers need to be able to access application without going through Shibboleth. Please pardon my ignorance in this framework.<br>
<br>
Any sample would be of great help.<br>
<br>
thank you, <br>
<br>
Don Starkey<br>
Lead Web Application Developer<br>
<br>
Center for Research Informatics<br>
The University of Chicago<br>
5454 S. Shore Drive, 1D<br>
Chicago, IL 60637<br>
Phone: 773-834-4809<br>
Email: <a href="mailto:dstarkey@bsd.uchicago.edu" target="_blank">dstarkey@bsd.uchicago.edu</a><br>
<br>
________________________________________<br>
From: users [<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>] on behalf of Boyd, Todd M. [<a href="mailto:tmboyd1@ccis.edu" target="_blank">tmboyd1@ccis.edu</a>]<br>
Sent: Friday, July 06, 2018 1:27 PM<br>
To: Shib Users<br>
Subject: RE: how to secure a spa application<br>
<br>
If it's a true SPA, why don't you just have Shibboleth protect the entire thing (which exists as a single page)?<br>
<br>
<br>
-Todd<br>
<br>
-----Original Message-----<br>
From: users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> On Behalf Of Starkey, Don [BSD] - CRI<br>
Sent: Friday, July 06, 2018 1:16 PM<br>
To: <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
Subject: how to secure a spa application<br>
<br>
Hello all,<br>
<br>
<br>
I need a spa application to be secured with Shibboleth, which is used by our university. The application is a single page angular application. We can secure a page on the server, so we do have the ability to access Shibboleth from our server. The workflow that I want to implement follows.<br>
<br>
1 user tries to access a specific landing page (protected by Shibboleth)<br>
2 user is re-routed to Shibboleth for credentials.<br>
3 NOT KNOWN - how to have the request rerouted to the SPA application. Is there a server side method available to generate a Jason Web Token for the Shibboleth Authenticated user and redirect to the SPA???<br>
<br>
I am very open to any workshops, or sample code that someone might have regarding Shibboleth's use in a single page application. I have searched the web for such a sample without any luck. Lack of Shibboleth integration would be a show stopper for us. Any help or references are greatly appreciated. I am sure someone has solved this problem. Please help me, I am running out of resources.<br>
<br>
Thank you for your time and any help that you may offer.<br>
<br>
Any HELP is GREATLY appreciated!<br>
<br>
<br>
Don Starkey<br>
Lead Web Application Developer<br>
<br>
Center for Research Informatics<br>
The University of Chicago<br>
5454 S. Shore Drive, 1D<br>
Chicago, IL 60637<br>
Phone: 773-834-4809<br>
Email: <a href="mailto:dstarkey@bsd.uchicago.edu" target="_blank">dstarkey@bsd.uchicago.edu</a><mailto:<a href="mailto:jjohnso3@bsd.uchicago.edu" target="_blank">jjohnso3@bsd.uchicago.edu</a>><br>
--<br>
For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=Nd1gv_ZWYNIRyZYZmXb18oVfc3lTqv2smA_esABG70U&r=SyA2YCI7HlJq7K2uJNf8XuCvAFTPQKOAB76WrUUQM8M&m=vBiaYGxznKnY0EIj_eh1aEACGVfJfZC2tL-f6AL_yWo&s=cOLEhpS75ZidqZKETo_XPQVqNyN3wT9PN-7rMNJmyPw&e=" rel="noreferrer" target="_blank">https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=Nd1gv_ZWYNIRyZYZmXb18oVfc3lTqv2smA_esABG70U&r=SyA2YCI7HlJq7K2uJNf8XuCvAFTPQKOAB76WrUUQM8M&m=vBiaYGxznKnY0EIj_eh1aEACGVfJfZC2tL-f6AL_yWo&s=cOLEhpS75ZidqZKETo_XPQVqNyN3wT9PN-7rMNJmyPw&e=</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
--<br>
For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=Nd1gv_ZWYNIRyZYZmXb18oVfc3lTqv2smA_esABG70U&r=SyA2YCI7HlJq7K2uJNf8XuCvAFTPQKOAB76WrUUQM8M&m=vBiaYGxznKnY0EIj_eh1aEACGVfJfZC2tL-f6AL_yWo&s=cOLEhpS75ZidqZKETo_XPQVqNyN3wT9PN-7rMNJmyPw&e=" rel="noreferrer" target="_blank">https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=Nd1gv_ZWYNIRyZYZmXb18oVfc3lTqv2smA_esABG70U&r=SyA2YCI7HlJq7K2uJNf8XuCvAFTPQKOAB76WrUUQM8M&m=vBiaYGxznKnY0EIj_eh1aEACGVfJfZC2tL-f6AL_yWo&s=cOLEhpS75ZidqZKETo_XPQVqNyN3wT9PN-7rMNJmyPw&e=</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>