<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">Hello Experts,<div class=""><br class=""></div><div class="">We have an application reporting CORS issue for the same use-case as mentioned in the below IDPv3 knowledge article</div><div class=""><br class=""></div><div class=""><a href="https://wiki.shibboleth.net/confluence/display/IDP30/Cross-origin+AJAX+requests+for+Shib-protected+resources" class="">https://wiki.shibboleth.net/confluence/display/IDP30/Cross-origin+AJAX+requests+for+Shib-protected+resources</a></div><div class=""><br class=""></div><div class="">My Current State: IDP version is v3.3.1 and is deployed in Tomcat 8 / JDK 8. W<span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class="">e are in parallel working to upgrade the IDP to v4 and Tomcat to v9 / Corretto JDK 11</span></div><div class=""><span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class=""><br class=""></span></div><div class="">Before going ahead with applying the workaround suggested, I wanted to reach out and get below questions answered. </div><div class=""><br class=""></div><div class="">Questions:</div><div class=""><br class=""></div><div class=""><b class=""><u class="">Work around for Current state:</u></b></div><div class=""><br class=""></div><div class="">1) <span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class="">The above article describes the workaround to be performed by adding the CORS filter from Jetty container into the IDP’s web.xml. </span>For my IDP v3 <u class="">deployed on Tomcat 8</u>, should I be using the equivalent Tomcat’s CORS filter (from link below)  in the IDP’s Web.XML ?</div><div class=""><a href="https://tomcat.apache.org/tomcat-8.0-doc/config/filter.html#CORS_Filter_and_HttpServletRequest_attributes" class="">https://tomcat.apache.org/tomcat-8.0-doc/config/filter.html#CORS_Filter_and_HttpServletRequest_attributes</a></div><div class=""><br class=""></div><div class=""><b class=""><u class="">Workaround for my future state:</u></b></div><div class=""><br class=""></div><div class="">2) I do not see a similar knowledge article for IDPv4 yet. So can you confirm if the same workaround is applicable for IDPv4 on Tomcat v9 too ? Or is there anything different ?</div><div class=""><br class=""></div><div class=""><br class=""></div><div class="">Please help me understand !</div><div class=""><br class=""></div><div class="">Thanks,</div><div class="">Prasanna</div></body></html>