Good morning!

When requesting a password reset from the main CAS login page (not via 
service) you receive a link like the following:

https://casdev.hvcc.edu/cas/login?pswdrst=TST-1-ATe9S6Bym5Vq8Prk6lMa9Pr86war7Ijf

However, if selected from a service's login page, you get the following

https://casdev.hvcc.edu/cas/login?pswdrst=TST-1-ATe9S6Bym5Vq8Prk6lMa9Pr86war7Ijf&service=https%3A%2F%2Fsite.blackboard.com%2Fwebapps%2Fbb-auth-provider-cas-BB5ca8ab8e56369%2Fexecute%2FcasLogin%3Fcmd%3Dlogin%26authProviderId%3D_124_1%26redirectUrl%3Dhttps%253A%252F%252Fhvcc-site.blackboard.com%252Fwebapps%252Fportal%252Fexecute%252FdefaultTab%26globalLogoutEnabled%3Dtrue

Not sure the service needs to be on this link. As I understand it, the 
transient service ticket is a one shot directed at the password reset 
component, so I am uncertain why the service would be necessary as the link 
also works with the ?service portion removed.

Is this something that ought to be removed from the link?

Thank you! 

Bill

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/bbd48f6b-b6dd-4c69-af51-447ff0455924%40apereo.org.

Reply via email to