Having problems with SAML auth on IdP version 4.1.3
Cantor, Scott
cantor.2 at osu.edu
Tue Jul 27 15:08:18 UTC 2021
On 7/27/21, 10:56 AM, "users on behalf of Duncan Sinclair" <users-bounces at shibboleth.net on behalf of d.sinclair at abertay.ac.uk> wrote:
> I've got a HAR file of the web traffic if you're interested, but having had a look at it myself, I'm beginning to
> think it's a 'SameSite' problem.
That would be on the way back in (you weren't specific about when this was happening), and I identified that in the original bug report you were looking at. That is 100% SameSite, I know that for certain.
> On the POST back to the Shibboleth Authn end-point, the shib_idp_* and JSESSION cookies are being blocked
> due to SameSite restrictions.
Yes, they would be, provided it happens after the two minute window (yet another wonderful gift from Google).
> Anybody got any tips on how to get the correct 'SafeSite' values set?
We documented that under SameSite in the wiki, and I also updated that page with the fact that proxying is broken without the workaround.
-- Scott
More information about the users
mailing list