how to ensure the security after enabling sso(single sign on) in OTM
If a sso provider passes a authentication ,and then passes the login information in http request including parametre 'appuid' to OTM,user can login HTM and use its function .
how can we avoid user pass the login information in http request including parametre 'appuid' manually ,just input the url in IE address column.
http://$otm_url/glog.webserver.servlet.umt.Login?appuid=***=***
******attachment text*****************
Oracle Transportation Management supports SSO, where a central application (the SSO provider)
authenticates users and then passes the login information to Oracle Transportation Management,