Skip to content

OIDC and Invalid authorization request state #9831

Answered by Nephilim84
Nephilim84 asked this question in Help
Discussion options

You must be logged in to vote

Hi @melohagan ,
Thanks for the quick reply, I am using F5 OIDC server to communication with our internal AD and allow SSO authentication.
Here is a snapshot of an auth failed request flow:

It looks like that the url encoding is missing somewhere so that the special characters contained in the state GET header is not correctly decoded by budibase-worker.

When a correct login is achieved, no special character appear in the state header so the authentication payload is correctly validated by the budibase-worker:

Hope this brings more understanding on this issue.

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@melohagan
Comment options

Answer selected by melohagan
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Help
Labels
3 participants