Feedback Requests
Complete

Sign-on rules now name their own address instead of inferring it

The sign-on rules applied to each protected site inferred the site's own address from the incoming request. Two cases break that: a client is not obliged to send the address at all, and the inference silently discards non-standard ports. Either leaves the gateway unable to tell which application a request belongs to, which presents as a login loop.

The deployment templates now state each site's address explicitly, so newly deployed and re-deployed sites are correct by default.

0 Comments

Sign in to comment

No comments yet. Be the first to share your thoughts!