Uploaded image for project: 'OpenAM'
  1. OpenAM
  2. OPENAM-9515

XUI does not enable Secure cookie flags for SSO tracking cookie on 13.5.0

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 13.5.0
    • Fix Version/s: 13.5.1, 14.0.0
    • Component/s: authentication, XUI
    • Labels:
    • Environment:
      OpenAM 13.5.0 (SSL enabled and with secure cookie enabled)
    • Sprint:
      AM Sustaining Sprint 28
    • Support Ticket IDs:

      Description

      On 13.5.0 the iPlanetDirectoryPro (SSO) cookie is not set to Secure even when this is enabled. The same exact setting worked on 13.0.0.

      curl -k https://openam.example.com:8443/openam/json/serverinfo/* 
      {"domains":[".example.com"],"protectedUserAttributes":[],"cookieName":"iPlanetDirectoryPro","secureCookie":true,"forgotPassword":"false","forgotUsername":"false","kbaEnabled":"false","selfRegistration":"false","lang":"en-US","successfulUserRegistrationDestination":"default","socialImplementations":[],"referralsEnabled":"false","zeroPageLogin":{"enabled":false,"refererWhitelist":[],"allowedWithoutReferer":true},"realm":"/","xuiUserSessionValidationEnabled":true}
      

      Notice that secureCookie is set to true which is what OPENAM-5255 (do for 13.0.0). Currently SSO cookie does not have the Secure cookie
      set.

      Test

      1. Clear all browser cookies
      2. Access OpenAM in XUI and login
      3. Check the iPlanetDirectoryPro cookie attributes.

      Observed

      The SSO cookie does not have the secure attribute (using XUI)

      Expected

      The SSO cookie (iPlanetDirectoryPro) have the secure attribute (using XUI)
      This worked in 13.0.0

        Attachments

          Activity

            People

            • Assignee:
              peter.major Peter Major [X] (Inactive)
              Reporter:
              chee-weng.chea C-Weng C
              QA Assignee:
              Joanna Wasilewska [X] (Inactive)
            • Votes:
              1 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 1h
                1h