Uploaded image for project: 'CXF-Fediz'
  1. CXF-Fediz
  2. FEDIZ-140

IDP caches outdated SAML Tokens

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.2.1
    • 1.3.0, 1.2.2
    • IDP
    • None

    Description

      I did some tests today with a SAML SSO trusted IDP. During these tests I've noticed that the Fediz-IDP will only redirect me once to the trusted 3rd party IDP for login. Then it caches my (3rd party) SAML token even if the token is not valid because the lifetime of that token ended. The result is, that I see an error page at the IDP, instead of getting redirected back again to my 3rd party IDP.

      I see two solutions for this issue.
      Option 1: Provide a "disable" option on the Fediz IDP to ignore lifetime of cached tokens.

      Option 2: Redirect back to 3rd Party IDP if cached token is not valid any longer.

      I think it would be good if both options could be provided within Fediz, leaving the choice to the user, depending on their use case.

      A current workaround is to disable token caching in the IDP.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            coheigea Colm O hEigeartaigh
            jan4talend Jan Bernhardt
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment