single sign on - Is it possible to modify exisiting shibboleth cookie? -
i have deployed 1 rest based application protected shibboleth sp , idp. of now, after authentication, pass uid via shibboleth cookie application , based on application take decision based on permission assigned uid.
recently, asked me if forge shibboleth cookie , change uid. not sure if possible @ , guess, if can able again shibboleth cookie change , discarded shibboleth.
so, possible somehow i.e. change uid in shibboleth cookie ? if yes have add 1 more layer of api security oauth,
Comments
Post a Comment