Skip to Content.
Sympa Menu

mace-opensaml-users - Re: [OpenSAML] Extra Query parameter (HTTP Redirect Binding)

Subject: OpenSAML user discussion

List archive

Re: [OpenSAML] Extra Query parameter (HTTP Redirect Binding)


Chronological Thread 
  • From: rangeli nepal <>
  • To: "Cantor, Scott E." <>
  • Cc: "" <>
  • Subject: Re: [OpenSAML] Extra Query parameter (HTTP Redirect Binding)
  • Date: Mon, 21 Mar 2011 14:10:11 -0400
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=qHKhKL8IIErlF5i2d3ZpBLqvE7Lkcp0sfW7A7THNRcUhOQQ8doN9zG7yw982VHGryo VdeAxlHCGthQyQXoON4NITHoQIXBcRqxQ6niJVr7ddd5GL1EeD1LgAHsLkHrkwRHWUIF g2pMqe8+Q6ONRAWawS/4t94LtKB63DPbMDaIk=

I am reading saml-binding-2.0, On page 17(line 566,567) says:

"A URL encoding MUST place the message entirely within the URL query
string, and MUST reserve the
rest of the URL for the endpoint of the message recipient."

I thought this means the protocol allows extra query string. Is this
not the intent of above statements?

I do agree we should not use the name of query parameter that
conflicts with the parameter name that protocol uses
Thank you.
rn
On Mon, Mar 21, 2011 at 1:51 PM, Cantor, Scott E.
<>
wrote:
> On 3/21/11 1:33 PM, "rangeli nepal"
> <>
> wrote:
>>I thought specification is mute about it. It just talks about
>>essential query parameters and some extent ordering. It does not talk
>>about extra query parameter.
>
> It does not allow them, because the binding itself makes use of those
> parameters. If you want to carry other information, you do it with SAML
> extensions.
>
> -- Scott
>
>



Archive powered by MHonArc 2.6.16.

Top of Page