Azure ACS - claims URL exposed in browser history - security hole?

Found this ACS official demo post http://www.fabrikamshipping.com/ while researching ACS.
In the application itself, when you log in with one of the providers (I chose Google), I see in the browser history a URL containing claims returned from ACS. This is the URL that begins with:

https://fabrikamshipping.accesscontrol.windows.net/v2/openid?context=pr%3dwsfederation%26rm%3dhttp%253a%252f%252ffabrikamshipping%252fcons ...

Going to this URL registers me in the application, even after clearing the entire browser cache and cookies .
Therefore, if I log into the application from some public computer and then log out, my account opens by going to the browser history at this URL.

I know this is the standard way to handle ACS Identity.
What am I missing here?

+5
source share
2 answers

I opened the same topic on the official Azure forums:

http://social.msdn.microsoft.com/Forums/en-US/windowsazuresecurity/thread/8f35d6d7-fe0d-4589-9502-54c85714979a

This seems like a known issue. I will update the answer here as soon as a solution is provided.

0

. URL- , cookie . , , . URL .

, URL- .

" . , - , , URL. , .

+1

All Articles