Troubleshooting 'stale request' error

Jason Rotunno jrotunno at swarthmore.edu
Tue Feb 14 14:30:43 UTC 2023


On Mon, Feb 13, 2023 at 1:21 PM Cantor, Scott <cantor.2 at osu.edu> wrote:

> > The day before we received this ticket we enabled the SameSite filter to
> address
> > this very issue.
>
> There are only a small set of scenarios, generally involving frames, where
> this is relevant. SSO mostly works fine without SameSite unless you're
> proxying, with a few edge cases that do not cause an error, just more
> frequent re-authentication.
>

 When you refer to proxying, are you talking about any type of proxy, or an
IdP proxy specifically? We do have Shibboleth behind an Apache instance
that's running mod_proxy_ajp.

-- 

Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505

*VERIFY before you click!!*
  - Attackers make their emails look like they come from someone they don't.
  - Attackers make links look like they go to websites they don't.
  - Attackers disguise malware as receipts, invoices, faxes, etc.

Forward suspicious emails to phishing at swarthmore.edu.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230214/16a06296/attachment.htm>


More information about the users mailing list