We say that CAS should only be run over SSL so I don't know how much support needs to be in for non-HTTPS scenarios.
That said, if it really is confusing, we can add a simple message to the JSP page (like we do for the login page). On Thu, Dec 8, 2011 at 2:41 PM, Marvin Addison <[email protected]>wrote: > > Should I file a bug in JIRA on this ? > > I agree this behavior is unhelpful, but all evidence suggests it's an > edge case configuration that would even allow access to /logout over > http. We strongly recommend deploying CAS on SSL. If anything I > would favor adding a security constraint to the default web.xml to > require a secure connection and add a comment to that effect so that > deployers have to work against best practice to experience this > behavior. > > Other opinions on how to address this? > > M > > -- > You are currently subscribed to [email protected] as: > [email protected] > To unsubscribe, change settings or access archives, see > http://www.ja-sig.org/wiki/display/JSG/cas-user > -- You are currently subscribed to [email protected] as: [email protected] To unsubscribe, change settings or access archives, see http://www.ja-sig.org/wiki/display/JSG/cas-user
