Uploaded image for project: 'OpenAM Agents'
  1. OpenAM Agents
  2. AMAGENTS-2956

Create option to Change Advice Format Value

    XMLWordPrintable

Details

    • Improvement
    • Status: Closed
    • Resolution: Fixed
    • 5.6.2.0, 5.7.0
    • Web Agents
    • None
    • 3

    Description

      Change the advice format to simple as composite_advice=<value> don’t include xml character or any security related parameter so that we can avoid relaxing css attack checks and url validation checks.  If they could be base64 encoded this should also address this issue.

      This is the web agent side fix - the idea would be that AM could handle any format, and with the default, current behaviour would be preserved. If set then the option would set the claim to use base64 url encoding.

      Attachments

        Issue Links

          Activity

            People

              alex.levin@forgerock.com Alex Levin
              alex.levin@forgerock.com Alex Levin
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: