Ray, The JSESSIONID cookie is created when I logout of CAS. It is a session cookie with the path /cas. If I delete that cookie manually from my browser's storage, I can log back in successfully. I can also achieve the same result by closing the entire browser (which removes the session cookie) and opening up a fresh browser and logging in.
This only impacts delegated authentication and I have only tested it with SAML with the delegated IdP being Azure. The OP has tested with OIDC. Jeremy On Thursday, December 19, 2019 at 9:38:26 AM UTC-8, rbon wrote: > > Jeremy, > > What application is creating the JSESSIONID? > I do not have that cookie. > > Ray > > On Wed, 2019-12-18 at 17:31 -0800, Jeremy Whaley wrote: > > I am experiencing a similar issue to your second issue. I am using > delegated authentication to Azure using pac4j SAML. If I log out and then > immediately log back in, the subsequent > login immediately fails with the following error: > > ERROR [org.apereo.cas.web.DelegatedClientWebflowManager] - <Delegated > client identifier cannot be located in the authentication request [ > https://xxxxxxxxxxx/cas/login?client_name=xxxxxxxxxxx]> > > If I remove the JSESSIONID cookie I can login without an issue. > > > I thought this pull request was somehow related, but was told otherwise: > > https://github.com/apereo/cas/pull/4513 > > > > On Monday, December 16, 2019 at 10:08:34 AM UTC-8, Matt Elson wrote: > > Running into two issues I could use some help with: > > First - in 6.1.2 if I build w/ Hazelcast and Hazelcast AWS Discovey via > the gradle overlay and have discovery enabled, > enabled(cas.ticket.registry.hazelcast.cluster.discovery.enabled=true) I > get the following stack trace: > > 2019-12-16 12:46:57,230 ERROR > [org.springframework.boot.SpringApplication] - <Application run failed> > org.springframework.beans.factory.BeanCreationException: Error creating > bean with name 'casTicketRegistryHazelcastInstance' defined in class > path resource > [org/apereo/cas/config/HazelcastTicketRegistryConfiguration.class]: Bean > instantiation via factory method failed; nested exception is > org.springframework.beans.BeanInstantiationException: Failed to > instantiate [com.hazelcast.core.HazelcastInstance]: Factory method > 'casTicketRegistryHazelcastInstance' threw exception; nested exception > is java.lang.NoClassDefFoundError: com/hazelcast/internal/util/StringUtil > > This worked fine in 6.0.x - not sure what's happening there. > > The second issue is that if I am using delegated pac4j auth w/ OIDC > (Azure specifically in my case, though suspect this would happen with > others), if I log out and then immediately logback in, the subsequent > login immediately fails with the following: > > "Caused by: org.pac4j.core.exception.TechnicalException: State parameter > is different from the one sent in authentication request. Session > expired or possible threat of cross-site request forgery" > > As near as I can tell from looking at http headers, what's happening is > the browser is sending the old, expired JSESSIONID (the cookie is not > explicitly removed on logout) when it goes to login again, then receives > a new Set-Cookie with a new JSESSION ID from CAS... but that new session > is missing the necessary state for OIDC (somehow forgotten or stuffed in > an old session), causing an error. > > Modifying TerminateSessionAction.java to tell the browser to erase the > cookie (something like in the session !=null stanza: > > Cookie jsession = new Cookie("JSESSIONID",""); > jsession.setMaxAge(0); > jsession.setPath("/"); > jsession.setSecure(true); > jsession.setHttpOnly(true); > response.addCookie(jsession); ) > > fixes the issue handily, as does throwing in a request.getSession(true) > in there - both don't seem proper, but having trouble finding out what's > happening specifically. > > Sorry, not terribly familiar with the Java ecosystem so having trouble > digging through the code myself. > > Anyway, any help anyone can bring would be appreciated while I try and > poke at both issues more. > > Thanks in advance, > Matt > > -- > > Ray Bon > Programmer Analyst > Development Services, University Systems > 2507218831 | CLE 019 | [email protected] <javascript:> > > I respectfully acknowledge that my place of work is located within the > ancestral, traditional and unceded territory of the Songhees, Esquimalt and > WSÁNEĆ Nations. > -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/b92f632c-c8ec-4ce7-8634-fd81d9816c7b%40apereo.org.
