[an error occurred while processing the directive]
![]() |
cosign-discuss at umich.edu |
general discussion of cosign development and deployment | |
I'm not finding anything in the spec about the ability to selectively
multi-factor protect individual url-patterns within a single filtered
resource. For example, we use a single instance of the Java cosign
filter to protect a suite of Peoplesoft applications, only some of which
we'd like to multi-factor protect. The rest would continue to require
only a single factor. Should I assume this would require as many filter
instances as there are url-patterns with different security
requirements?
It would be nice to see the multi-factor capability extended to re- auth.
Our re-authenticated resources are not really distinct from the rest of
our application content. As mentioned above, we'll turn on multi- factor
for some of that content and would like to be able to re-authenticate
for certain sub-components with the same factors used to authenticate.