Re: Shield specific *path* from rewriting in a rewritten domain?
Laszlo Gercsov <[email protected]>
| Newsgroups | gmane.education.ezproxy |
|---|---|
| Message-ID | <MEAPR01MB5221CB06908DBE0856928C4CD69F0@MEAPR01MB5221.ausprd01.prod.outlook.com> |
Hi Michael. I tried configuring the SPUEdit in my config, but it did not work. I think the URL was too long. But I got it to work by adding :- NeverProxy auth.nih.gov I think that will be OK as long as the host auth.nih.gov is only used during SSO. Best, Laszlo. ________________________________ From: EZproxy List <[email protected]> on behalf of Michael Berkowski <[email protected]> Sent: Tuesday, 1 October 2019 3:29 AM To: [email protected] <[email protected]> Subject: Re: [EZPROXY-L] Shield specific *path* from rewriting in a rewritten domain? Thank you for responses thusfar - I've been debugging the SAML redirect chain and it seems like the issue is a mismatch between the SAML service provider beginning from a proxy source like https://auth-nih-gov.ezp3.lib.umn.edu/affwebservices/public/saml2authnrequest?ProviderID=urn:mace:incommon:umn.edu&RelayState=https%3A%2F%2Fauth.nih.gov%2FFederationPortal%2FPortalLDAP.asp%3FTARGET%3Dhttps://federation.nih.gov/ncbifedauth/cit.cgi%253Fcmd%253Dlogin%2526version%253D2%2526auth%253Duniversity_of_minnesota<https://protect-au.mimecast.com/s/aPY-CK1DOrCBE8mnfMjD35?domain=auth-nih-gov.ezp3.lib.umn.edu> This redirects to our IdP as expected, and users can complete the login. But the SAML post-login redirect returns to an unproxied federation.nih.gov/ncifedauth<https://protect-au.mimecast.com/s/HlBwCWLVn6iP9zGBuBQZxL?domain=federation.nih.gov> URL. I would guess that the browser does not have cookies set for the correct domains at that point, or the SAML assertion has a domain mismatch. It ends in a 500 error at https://auth.nih.gov/affwebservices/public/saml2assertionconsumer<https://protect-au.mimecast.com/s/NltQCMwGj8CROxWZfJRGbX?domain=auth.nih.gov>. So it starts the auth from within the proxy but completes it outside the proxy. I was hoping to exit the proxy earlier (when listing 3rd party logins) so any nih.gov<https://protect-au.mimecast.com/s/s-WICXLW6Diq5B0YSx5AdE?domain=nih.gov> session cookies would be set on the correct domains, and the SAML redirects could start and complete consistently outside the proxy. On Sun, Sep 29, 2019 at 6:39 PM Laszlo Gercsov <[email protected]<mailto:[email protected]>> wrote: Hi Michael. I believe you can use SPUEdit for this. eg SPUEdit @^https://www.ncbi.nlm.nih.gov/account/partners$@https://www.ncbi.nlm.nih.gov/account/partners@ir<https://protect-au.mimecast.com/s/dINSCNLJxkiElVXBSRZ8zm?domain=ncbi.nlm.nih.gov> You should have the SPUEdit line before any stanzas for the same host. Best, Laszlo. Laszlo Gercsov Senior Systems Analyst Library Systems Library | Level 4 16 Macquarie Drive Macquarie University, NSW 2109, Australia T: +61 2 9850 6533 | F: +61 2 9850 7568 M: + 61 402 175 101 | mq.edu.au/library<http://mq.edu.au/> [Macquarie University]<http://mq.edu.au/> CRICOS Provider Number 00002J. Think before you print. Please consider the environment before printing this email. This message is intended for the addressee named and may contain confidential information. If you are not the intended recipient, please delete it and notify the sender. Views expressed in this message are those of the individual sender, and are not necessarily the views of Macquarie University ________________________________ From: EZproxy List <[email protected]<mailto:[email protected]>> on behalf of Michael Berkowski <[email protected]<mailto:[email protected]>> Sent: Saturday, 28 September 2019 2:16 AM To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>> Subject: [EZPROXY-L] Shield specific *path* from rewriting in a rewritten domain? Hi all, I am experimenting with the PubMed stanza as it originates on https://help.oclc.org/Library_Management/EZproxy/Database_stanzas/PubMed<https://protect-au.mimecast.com/s/lRfnCOMK7Yc0R54KSPW3HF?domain=help.oclc.org> - in particular I wanted to find a way to get PubMed's "Sign in to NCBI" links to work through UMN's federated login so that users who follow those individual sign in links while already proxied drop out of EZproxy and hit the links directly. I thought I might find a way to prevent a specific URL path from ever being rewritten on an otherwise rewritten (proxied) domain but not finding any such feature. Using Find/Replace with ^A does not seem to work in this instance because the links are originally spelled out in the HTML like: authid="university_of_minnesota" href="?authid=university_of_minnesota" I can't use Replace with ^A here becuase it only works to follow http:// or https://. AnonymousURL is not appropriate because we would not want it rewritten at all, rather than rewritten but unauthenticated. I attempted to stack two Find/Reaplce pairs first transforming the above into a full URL, then rewriting it with ^A, but found that does not work either. Is there a directive that would allow us to just prevent URLs with the relevant path from being rewritten: https://www.ncbi.nlm.nih.gov/account/partners<https://protect-au.mimecast.com/s/Oys9CP7L1NfoGvMxSrUgju?domain=ncbi.nlm.nih.gov> ? This is all only an experiment after we received a support question from a user who attempted to do use the Sign in to NCBI links while already in the proxy. I am first determining if it is possible to un-proxy this section of the site before finding out what the actual repercussions of doing that would be. Thank you for any input, -- ++++++++++++++++++++ Michael Berkowski University of Minnesota Libraries [email protected]<mailto:[email protected]> 612.626.6137 PGP Public Key: http://z.umn.edu/mjbpubkey<https://protect-au.mimecast.com/s/wftuCQnM1Wf3ABrWH9mdl9?domain=z.umn.edu> ++++++++++++++++++++ ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/8q-BCRONg6sRmnBLf03OkQ?domain=listserv.oclclists.org> -- ++++++++++++++++++++ Michael Berkowski University of Minnesota Libraries [email protected]<mailto:[email protected]> 612.626.6137 PGP Public Key: http://z.umn.edu/mjbpubkey<https://protect-au.mimecast.com/s/wftuCQnM1Wf3ABrWH9mdl9?domain=z.umn.edu> ++++++++++++++++++++ ________________________________ To unsubscribe from the EZPROXY-L list, click the following link: http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1<https://protect-au.mimecast.com/s/8q-BCRONg6sRmnBLf03OkQ?domain=listserv.oclclists.org> ******************************************************************** If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences, you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>. Or email [email protected] including the relevant text below in the body of the email: • To unsubscribe: "unsubscribe EZPROXY-L" • To receive EZPROXY-L in digest form: "set EZPROXY-L digest" • To set your options to no mail: "set EZPROXY-L nomail" • To receive these messages in the future "set EZPROXY-L mail" To contact the list owners directly please send your message to [email protected]. If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum. To unsubscribe from all OCLC marketing email communications (including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters), please email us at [email protected].