But in 4.0.x there wasn't a cipher to begin with right? The key is still matched with what there is the session or is all of that no longer stored in the session? I thought it still was actually.
About the external redirect: I always thought that would only be used for an end-state. Wouldn't I lose the context I'm currently in? I think the whole idea of the redirect="true" attribute is to exactly accomplish this. Maybe I could do an external redirect with a flow key, but that is essentially the same as doing it with redirect=true and I still have the issue of the too long URI. Same goes for the JSP way. I have the feeling that (since 4.0) didn't have the encrypted execution keys, it's still rather safe without the cipher. Or at least as safe as it was in 4.0. Can you confirm that? Or did something else change that makes it less secure than it was in 4.0? Thanks for you time btw. Auke On Friday, March 4, 2016 at 10:09:24 PM UTC+1, Misagh Moayyed wrote: > > You always want to post to @apereo.org mailing lists. > > > > Losing the cipher certainly matters security-wise, yes. Replay attacks may > be possible. So to start with: > > > > 1. Lose the cipher, see if the issue goes way. If so, put the > cipher back and investigate the failing factor. If not, move on. > > 2. See if an externalRedirect semantic works. > > 3. Manually issue a redirect in your JSP/Action/etc > > > > *From:* [email protected] <javascript:> [mailto:[email protected] > <javascript:>] *On Behalf Of *aukevanleeuwen > *Sent:* Friday, March 4, 2016 8:53 AM > *To:* CAS Community <[email protected] <javascript:>> > *Subject:* [cas-user] Encrypted flow keys and redirect=true in webflow > > > > Hello, > > > > I'm in the middle of an upgrade to 4.2.x, however I have some problems > with the new encrypted flow keys in CAS. > > > > I have some extensions to the webflow for which I want to use > redirect="true" on a view state in login-webflow: > > > > <view-state id="askPasswordForSocialRegistrationView" view= > "askPasswordForSocialRegistrationView" model="social" redirect="true"> > <transition to="checkPassword"/> > </view-state> > > > Now if I do that I get a redirect to a *very* long url. It differs a bit > (probably because the default is a compressed cipher), but it's in the > range of 6000 - 9000 characters. That is a bit long for a redirect (at > least Tomcat has a default maximum of 8096 characters (top of my head) > before it will bail out). > > > > I really need the redirect, so what are my options? Can I lose the cipher? > Does it matter security-wise? > > > > PS. Sorry if I double posted this to the old groups? I got a message > saying the other (Jasig) lists were decomissioned. > > > > Auke > > -- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected] <javascript:>. > Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/ > . > -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
