CAS 6.1.3 PM password reset link question.

28 views
Skip to first unread message

William Jojo

unread,
Jan 24, 2020, 8:13:39 AM1/24/20
to CAS Community
Good morning!

When requesting a password reset from the main CAS login page (not via service) you receive a link like the following:


However, if selected from a service's login page, you get the following


Not sure the service needs to be on this link. As I understand it, the transient service ticket is a one shot directed at the password reset component, so I am uncertain why the service would be necessary as the link also works with the ?service portion removed.

Is this something that ought to be removed from the link?

Thank you! 

Bill

Misagh Moayyed

unread,
Jan 29, 2020, 5:23:54 AM1/29/20
to CAS Community
Not sure the service needs to be on this link. As I understand it, the transient service ticket is a one shot directed at the password reset component, so I am uncertain why the service would be necessary as the link also works with the ?service portion removed.

Is this something that ought to be removed from the link?

No. 

Let's say you start with Service A and attempt to login via CAS, and then you are forced to reset your password. When you have completed the password flow, the service parameter is re-collected again to redirect you back to Service A, so you can resume.

The service parameter is always optional, whether you're resetting passwords or doing anything else. 
Reply all
Reply to author
Forward
0 new messages