Bug Reports
Complete
Every single-sign-on protected application redirects in a loop
After an identity platform upgrade, all applications behind a sign-on gateway redirected endlessly instead of logging in. No error page was shown, and the gateways reported themselves healthy throughout.
The release only honours forwarded request headers when the connection arrives from a trusted network. The gateways' back-channel call left the network and re-entered from an external address, so its headers were discarded and every token exchange was rejected.
Resolved by the follow-up patch release.
0 Comments
Sign in to comment
No comments yet. Be the first to share your thoughts!
