Uploaded image for project: 'CXF-Fediz'
  1. CXF-Fediz
  2. FEDIZ-232

'wctx' parameter mandatory but protocol does not require

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 1.5.0, 1.4.6
    • None
    • None

    Description

      For logins which are not initiated by a valid session on the RP side the user cannot be authenticated because the wctx parameter is missing or has the wrong value.

      There are at least two scenarios in which this causes a unwanted behaviour of the system.

      • First is if the IDP/login page is bookmarked and returns only later after the session on the RP is timed out. 
      • Second is something similar to a IDP initiated login flow. It's not in the WS federation protocol specification but according to our tests fediz could easily allow that if the 'wctx' check is removed. 

      In the protocol specification the 'wctx' parameter is also only optional, where fediz expects it to be always present. There is a comment with respect to CSRF prevention but our security team didn't see the case for this since there is no passive way of authentication is used. In fact it's the actual authentication request that is supposed to be protected, but we don't see the need.

       

      One option (if the CSRF case is valid) would be to at least disable the 'wctx' state validation by setting a flag.

      Attachments

        Issue Links

          Activity

            People

              coheigea Colm O hEigeartaigh
              cifi Christian Fischer
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 10m
                  10m