Replies: 2 comments 4 replies
-
Oh yes ! It would be really good! |
Beta Was this translation helpful? Give feedback.
0 replies
-
This would of course be possible to allow someone to configure. However I'd like to caution against using this option as it's far from a robust security measure, although it suggests it is. ForceAuthn cannot really be enforced, it's just a hint mostly. As mod_auth_mellon allows unsolicited (idp-first) SSO, there's a trivial way around this security measure in many cases if you want to. |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Currently the AuthnRequest attribute ForceAuthn is always "false". Could that be determined by a configuration directive instead?
mod_auth_mellon/auth_mellon_handler.c
Line 3017 in d5cfa39
Beta Was this translation helpful? Give feedback.
All reactions