leastprivilege.com
Beware of WIF HTTP Modules and Default Configuration
Most samples I know of – as well as FedUtil generated configuration set a preCondition=”managedHandler” for the WIF HTTP modules. This means that the modules (and thus the protection of…