Using JSESSIONID to bypass SSO

Vivian Escalante
Contributor
October 9, 2020

I've been following this documentation, but when I try to hit the login page it still redirects me to the SSO login page.

First call:

curl -u <user>:<password> -X POST -d '{"username": "<user>","password": "<password>"}' -H "Content-Type: application/json" https://<base_url>/rest/auth/1/session

I grab the JSESSIONID value from the response and then try to hit the login page

curl -b "JSESSIONID=<JSESSIONID_value>" https://<base_url>/login.jsp -I

This redirects me to the SSO login page. Anything I'm doing wrong here? Thanks! 

0 answers

Suggest an answer

Log in or Sign up to answer