The standard URL validation mapping from Cosign Config is:


Below that, some configs I've seen define their own protected url pattern as: 

    <service name=""> <protected>/*</protected> </service>

to 'cover everything', and some put (2):

    <service name=""> <protected>/access/*</protected> 

My web.xml is:

        <!-- the following entry is required for URL validation -->
                <filter-name>Cosign Authentication Filter</filter-name>
        <!-- CoSign authentication on a URL. -->
                <filter-name>Cosign Authentication Filter</filter-name>

Now, if I use (1), I get the dreaded Browser Loop
If I use (2), I get the error 'Cosign filter defined to pickup URL but no 
service defined.'

So my question is: should the service/protected pattern in cosignConfig.xml 
overlap /cosign/valid/ - or would that be causing the browser loop that I'm 
If not, how do I avoid getting 'no service defined' when the browser redirects 
to /cosign/valid?
It seems like i've somehow configured a Catch-22..


Try New Relic Now & We'll Send You this Cool Shirt
New Relic is the only SaaS-based application performance monitoring service 
that delivers powerful full stack analytics. Optimize and monitor your
browser, app, & servers with just a few lines of code. Try New Relic
and get this awesome Nerd Life shirt!
Cosign-discuss mailing list

Reply via email to