Howard, > So generally if foo.com <http://foo.com/> redirects to CAS with > service=foo.com <http://foo.com/>, and then gets back a service ticket, and > then redirects the browser with that ticket= to bar.com <http://bar.com/>, > then when bar.com <http://bar.com/> tries to validate the ticket with > validate?service=bar.com <http://bar.com/> the request is rejected because > “bar.com <http://bar.com/>” does not match the service ”foo.com > <http://foo.com/>” presented when the ticket was issued.
This is helpful. If I were to reword this, the protocol allows the CAS server to associate the ticket with an intended service, but there’s nothing for a CAS client to check, and this is in the protocol rather than the payload. Is that correct? It’s interesting to me since SAML took the exact opposite approach, relying on the service to discard any inappropriate assertions. I haven’t really thought through pros and cons. Thanks for your help, Nate. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
