Forum Discussion
clientless - sso
Would you need to do all of that? Assuming that the FIRST request is a POST to "/auth" with credentials, subsequent requests should all come with the session cookie, so that:
-
You could technically only enable clientless-mode for this request, and
-
Simply set the pools in the ACCESS_ACL_ALLOWED event for everything.
All subsequent requests will have the session cookie, so they should all skip to the ACCESS_ACL_ALLOWED event. You might also want to send a "reject" response if the user attempts to request a URI other that "/auth" without the session cookie.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com