[JIRA] [saml-plugin] (JENKINS-31043) SAML plugin can't auth with CSRF protection enabled

27 views
Skip to first unread message

mdonohue@java.net (JIRA)

unread,
Oct 20, 2015, 2:23:01 AM10/20/15
to jenkinsc...@googlegroups.com
mdonohue created an issue
 
Jenkins / Bug JENKINS-31043
SAML plugin can't auth with CSRF protection enabled
Issue Type: Bug Bug
Assignee: Ben McCann
Components: saml-plugin
Created: 20/Oct/15 6:22 AM
Priority: Critical Critical
Reporter: mdonohue

I have SAML configured to auth users. We recently decided to turn on CSRF protection, but discovered it prevents anyone from authenticating via SAML. The securityRealm/loginFinished page produces a "missing CSRF crumb" error.

Add Comment Add Comment
 
This message was sent by Atlassian JIRA (v6.4.2#64017-sha1:e244265)
Atlassian logo

mdonohue@java.net (JIRA)

unread,
Oct 20, 2015, 11:07:02 PM10/20/15
to jenkinsc...@googlegroups.com
mdonohue commented on Bug JENKINS-31043
 
Re: SAML plugin can't auth with CSRF protection enabled

The CSRF protection can be disabled in some circumstances - I wrote a patch against the saml plugin to exclude the loginFinished endpoint from CSRF protection. This gets rid of the missing crumb error, but login does not complete either.

This is the patch: https://github.com/mdonohue/saml-plugin/commit/717fd8cb75b5f8ab65a48fcafded25c1f802f7ac

benjamin.j.mccann@gmail.com (JIRA)

unread,
Oct 20, 2016, 1:33:03 PM10/20/16
to jenkinsc...@googlegroups.com
Ben McCann assigned an issue to Unassigned
 
Change By: Ben McCann
Assignee: Ben McCann
This message was sent by Atlassian JIRA (v7.1.7#71011-sha1:2526d7c)
Atlassian logo

mdonohue@java.net (JIRA)

unread,
Oct 21, 2016, 12:13:01 AM10/21/16
to jenkinsc...@googlegroups.com

mdonohue@java.net (JIRA)

unread,
Oct 21, 2016, 12:16:01 AM10/21/16
to jenkinsc...@googlegroups.com
mdonohue commented on Bug JENKINS-31043
 
Re: SAML plugin can't auth with CSRF protection enabled

Patch was merged, and plugin released back in February.

mdonohue@java.net (JIRA)

unread,
Oct 21, 2016, 12:16:02 AM10/21/16
to jenkinsc...@googlegroups.com
mdonohue closed an issue as Fixed
 
Change By: mdonohue
Status: Open Closed
Resolution: Fixed
Reply all
Reply to author
Forward
0 new messages