Hello,
I'm trying Simple SSO Security and I found a security Issue.
Indeed, the Phone & Company could be set in the SSO Url but it's not include in the HASH. So If I intercept the http request, I can change my phone and company.
The phone is not really important for me, but I would like to separate solutions, articles & ticket between company. With this, I can't be sure that a customer will not try to access ticket or article from other company.