Bug Reports
Complete

Every single-sign-on protected application redirects in a loop

After an identity platform upgrade, all applications behind a sign-on gateway redirected endlessly instead of logging in. No error page was shown, and the gateways reported themselves healthy throughout.

The release only honours forwarded request headers when the connection arrives from a trusted network. The gateways' back-channel call left the network and re-entered from an external address, so its headers were discarded and every token exchange was rejected.

Resolved by the follow-up patch release.

0 Comments

Sign in to comment

No comments yet. Be the first to share your thoughts!