Skip to content

Conversation

@rullzer
Copy link
Member

@rullzer rullzer commented Dec 17, 2018

Because the redirect from the SAML/SSO endpoint is a POST the lax/strict
cookies are not properly send.

Note that it is not strictly requried on this endpoint as we do not need
the remember me data. Only the real session info is enough. The endpoint
is also already protected by a state token.

Signed-off-by: Roeland Jago Douma [email protected]

Because the redirect from the SAML/SSO endpoint is a POST the lax/strict
cookies are not properly send.

Note that it is not strictly requried on this endpoint as we do not need
the remember me data. Only the real session info is enough. The endpoint
is also already protected by a state token.

Signed-off-by: Roeland Jago Douma <[email protected]>
@mario
Copy link
Contributor

mario commented Dec 17, 2018

👍

@rullzer rullzer added 3. to review Waiting for reviews and removed 2. developing Work in progress labels Dec 17, 2018
@rullzer
Copy link
Member Author

rullzer commented Dec 17, 2018

/backport to stable15

@rullzer
Copy link
Member Author

rullzer commented Dec 17, 2018

/backport to stable14

@rullzer
Copy link
Member Author

rullzer commented Dec 17, 2018

/backport to stable13

@rullzer rullzer merged commit 2d07c58 into master Dec 17, 2018
@rullzer rullzer deleted the fix/login_flow_with_saml_ios branch December 17, 2018 13:17
@backportbot-nextcloud
Copy link

backport to stable15 in #13123

@backportbot-nextcloud
Copy link

backport to stable14 in #13124

@backportbot-nextcloud
Copy link

backport to stable13 in #13125

@marinofaggiana
Copy link
Member

👍

@wiswedel
Copy link
Contributor

I have a client with (potentially) the same problem on the Windows client. Could this fix that too?

@mario
Copy link
Contributor

mario commented Dec 17, 2018

Yes @wiswedel :)

@wiswedel
Copy link
Contributor

@mario Great, so with 15.0.1 this should be fixed for them then?

@rullzer
Copy link
Member Author

rullzer commented Dec 17, 2018

I'm not sure about windows as it might be a different issue. But maybe.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants