Quantcast
Channel: Claims based access platform (CBA), code-named Geneva forum
Viewing all articles
Browse latest Browse all 2535

prevent parameter 'wfresh' alteration

$
0
0

When the Pelaying Party sends an authentication request with fresh = 0 then user receive logon form.

User may change GET request in Browser to wfresh = 1 and successfully authenticated without logon form.

How to prevent the parameter 'wfresh' alteration?

Is the only one solution for RP to use SAMLP (ForceAuth=true) with signature instead of WS-Fed (wfresh=0)?

Viewing all articles
Browse latest Browse all 2535

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>