<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Agreed that this is odd.  I have been able to reliably reproduce it with the following steps:</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<ol>
<li>Trigger SSO with HTTP-POST from an SP at an "external" domain from the IdP</li><li>"Reload" the SP session several times (I've been using the /Shibboleth.sso/Login endpoint), SSO works</li><li>Wait 2 minutes</li><li>Reload the <span style="font-family: Calibri, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">
SP </span>session again, SSO works</li><li>Reload the <span style="font-family: Calibri, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">SP</span> session again, SSO fails and prompts for credentials</li><li>Clear IdP's JSESSIONID cookie</li><li>Go back to SP and reload the session again, SSO works</li><li>Reload the <span style="font-family: Calibri, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">
SP </span>session again, SSO fails and prompts for credentials<br>
</li></ol>
<div>Continuing to clear the JSESSIONID cookie will allow for one successful SSO via HTTP-POST before failing again.  If I don't remove the JESSIONID cookie then I keep getting the login page.</div>
<div><br>
</div>
<div>This feels like Chrome's 2-minute "Lax + POST" window, let me know if there's more info I should provide.</div>
<div><br>
</div>
<div>Thanks,</div>
<div>Ryan</div>
<div><br>
</div>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Friday, August 14, 2020 11:32<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Bit of a SameSite update</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">On 8/14/20, 12:19 PM, "users on behalf of Ryan Larscheidt" <users-bounces@shibboleth.net on behalf of larscheidt@wisc.edu> wrote:<br>
<br>
>    I just want to verify that the "do nothing" option is still viable, perhaps I missed a setting?<br>
<br>
I think it is for the most part, but the use of frames was creating some unusual behavior because that prevented the local storage load (it was a hidden iframe and so it wouldn't work unless I could keep JSESSIONID stable).<br>
<br>
I haven't seen any issues in normal cases and if you are, something else is going on.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>