Stale session errors after upgrading to 5.2.2
Wessel, Keith
kwessel at illinois.edu
Wed May 20 18:46:53 UTC 2026
Thanks, Scott. This was screaming samesite behavior to me. Don't know how we missed that in the release notes.
So, with this change, do I still even need the samesite settings in idp.properties?
# These control operation of the SameSite filter, which is off by default.
idp.cookie.sameSite = None
idp.cookie.sameSiteCondition = shibboleth.Conditions.TRUE
The documentation makes it sound like they're still of some value to the running IdP.
Also, there's a samesite property documented in the release notes for 5.2.0that isn't documented in the IdP 5 samesite docs: idp.cookie.sameSite.autoDisableFilter. What's the purpose of this?
Thanks again, we all need an occasional RTFM to keep us humble.
Keith
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Scott Cantor via users
Sent: Wednesday, May 20, 2026 12:49 PM
To: Shib Users <users at shibboleth.net>
Cc: Scott Cantor <scott at restingparrotsoftware.com>
Subject: Re: Stale session errors after upgrading to 5.2.2
That's a SameSite issue, and is documented as the first issue under 5.2.0 under "changes to defaults or behaviors".
Use anything but Chrome and you will find that everyone else abandoned the stupid idea of defaulting unmarked cookies to Lax, if they even did it to begin with.
-- Scott
--
For Consortium Member technical support, see https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!DZ3fjg!6ZanCwxYQrtfZmo1a-JJJri0awndJsN6kxfTUoIzFLEmMPetqrpWmhfN62NPYokuq3x9Dujgy7nJcM7v9_df$
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list