[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [saml-dev] Empty Target Value Acceptable in SAML 1.1?
Scott Cantor wrote on 1/15/2005, 2:39 PM: > > As a guideline, I think a 2.0 SP should always have a "default" place > to go > if a response comes in with no relay state. The spec says that the IdP > can > send some kind of predefined string, but I'm not sure how useful that > really > is. Note that the SP also has a "safer" option of using a cookie that only goes from its site to the browser and back, without going to the IdP. Personally, I think that the cookie would be the preferred method for most SPs and the relaystate would be unspecified. Conor
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]