[mitreid-connect] Suspicious behaviour when invalid redirect uri is detected?

Justin Richer jricher at mit.edu
Fri Dec 2 15:24:47 EST 2016


This is expected but I understand it could be disconcerting. Your session to the IdP is not terminated on an error. Not only would that be an awful user experience in most cases, in some instances where the server is deployed in an SSO environment you *can’t* really kill the session anyway.

 — Justin

> On Dec 1, 2016, at 11:32 AM, Luiz Omori <luiz.omori at duke.edu> wrote:
> 
> Hi,
>  
> Interesting thing happened this morning while testing an application. I was using the Implicit flow and put a redirect url that hadn’t been configured in the server yet. The proper error message was displayed but I’ve noticed that may name was displayed on the top-right corner and could access some features from the server as if I was logged in to it. Is this by expected? I was kind of expecting that upon error my login would be aborted.
>  
> Regards,
> Luiz
>  
> (Pictures removed...)
> _______________________________________________
> mitreid-connect mailing list
> mitreid-connect at mit.edu <mailto:mitreid-connect at mit.edu>
> http://mailman.mit.edu/mailman/listinfo/mitreid-connect <http://mailman.mit.edu/mailman/listinfo/mitreid-connect>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.mit.edu/pipermail/mitreid-connect/attachments/20161202/985dfe9b/attachment.html


More information about the mitreid-connect mailing list