Bug: SBS interrupt redirect loses its nonce after StepUp
Maintainers usually reply within 3 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 82/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- php
- Domain
- authentication
Research direction
Start in StepupAssertionConsumer and trace how the stored original SBS response is handled after StepUp; the issue identifies handleSramInterruptCallout() as the relevant call. Find the existing combined-flow scenario and its SBS mock, then add assertions for the redirect nonce and continuation after SBS. Done when the original nonce is preserved and the listed StepUp-only and SBS flows still work.
Written by the indexing model from the issue text.
Description
When an SP requires both StepUp and an SRAM/SBS check, SBS may return an interrupt response with a nonce. EngineBlock stores that nonce and performs StepUp first. After StepUp returns, EngineBlock redirects the browser to SBS with an empty nonce query parameter instead of the nonce SBS issued. This may prevent SBS from resuming the interrupt flow.
In StepupAssertionConsumer , EngineBlock detects the stored SRAM step but passes the StepUp Gateway response to handleSramInterruptCallout() rather than the original response containing the SBS nonce.
Steps to reproduce
- Configure an SP to require StepUp and SRAM collaboration; enable eb.feature_enable_sram_interrupt .
- Configure SBS to return an interrupt response with a nonce, such as my-nonce .
- Log in through the IdP and complete StepUp.
- Inspect the browser's redirect to SBS.
Actual result
The SBS redirect contains an empty nonce, such as ?nonce= .
Expected result
The redirect contains the nonce from SBS's original interrupt response, such as ?nonce=my-nonce . The user can then complete the SBS step and continue through consent to the SP.
Acceptance criteria
• The SBS redirect after StepUp carries the original SBS nonce.
• A regression test asserts the nonce in the redirect and verifies the flow can continue after SBS.
• Existing StepUp-only, SBS-authorized, and SBS-interrupt-without-StepUp flows continue to work.
Technical hint: Pass the stored original response to handleSramInterruptCallout() in StepupAssertionConsumer . The existing combined-flow scenario does not assert the nonce, and its SBS mock ignores the redirect query string.
- Dominant language
- PHP
- Stars
- 17
- Forks
- 25
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 2
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from OpenConext/OpenConext-engineblock
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
OpenConext/OpenConext-engineblock#2122 · 4 comments ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
OpenConext/OpenConext-engineblock#2040 ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
OpenConext/OpenConext-engineblock#2015 ·
Maintainers usually reply within 3 days
-
maintenance
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
OpenConext/OpenConext-engineblock#1960 · 2 comments ·
Maintainers usually reply within 3 days
-
fix autocorrect in WAYF to prevent unwanted spelling correctionPossibly taken @kayjoosten claimed this 3 days ago. Opendiscovery UI
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
OpenConext/OpenConext-engineblock#1734 · 2 comments ·
Maintainers usually reply within 3 days
All issues in OpenConext/OpenConext-engineblock
Similar issues
-
📚 Documentation: Placeholder link `link-to-realtime-docs` in Flutter SDK changelogPossibly taken @ShyneChikwapulo claimed this today. Openapi / realtime product / auth product / messaging product / vcs
Difficulty 1/5 Under an hour Newbie friendliness 82/100
appwrite/appwrite#14272 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
Boavizta/boaviztapi#580 · 1 comment ·
-
Add PrestashopOpenrequest
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
endoflife-date/endoflife.date#11303 ·
Maintainers usually reply within 1 day
-
0. to triage enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
Maintainers usually reply within 1 day