Skip to content

Token cookie can exceed 4kb #203

@BryceDFisher

Description

@BryceDFisher

Per RFC2109, Cookies cannot exceed 4kb. I have recently run into a situation where the token cookie set in samlsp/cookie.go:83 can exceed the 4kb limit if used with a user that has a large number of the roles claim. Need to come up with an alternate method of transmitting the information to the service provider code during the redirect than storing it in the cookie.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions