Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

TypeThreatMitigation

Information Disclosure

If HTTPS is not used, the PGT can be stolen, which is extremely critical as it represents as SSO identity.

Always use HTTPS for /proxy url.

SpoofingThe attacker can generate proxy tickets for other services and discover user's attributes.Limit as much as possible the services definition : not a very efficient solution, we should never reach that point !
Information disclosureGET parameters ! very important information should be posted TODO 

Threats on "proxy callbacks" attack surface

...