SSO cookie reset before authentication is complete on subsite

Created on 13 September 2011, over 13 years ago
Updated 15 May 2025, 2 days ago

After SSO (chocolatechip) cookie validation on the slave the SSO cookie is resent, this time with cookie['master'] equal to FALSE (because it's set on the slave).

It's difficult to define in reproducible steps, but should authentication fail on the subsite, and the SSO cookie is reset, then the next requests will never authenticate, because the SSO cookie will no longer validate due to having been generated on the slave.

πŸ› Bug report
Status

Closed: outdated

Version

2.0

Component

Code

Created by

πŸ‡ΊπŸ‡ΈUnited States coltrane

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024