Bug: SBS interrupt redirect loses its nonce after StepUp
Los mantenedores suelen responder en 3 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 82/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- php
- Área
- authentication
Línea de trabajo
Empieza en StepupAssertionConsumer y rastrea cómo se gestiona la respuesta SBS original almacenada después de StepUp; el issue identifica handleSramInterruptCallout() como la llamada relevante. Encuentra el escenario existente del flujo combinado y su mock de SBS, y añade aserciones para el nonce de redirección y la continuación después de SBS. El trabajo estará terminado cuando se conserve el nonce original y los flujos indicados, solo de StepUp y de SBS, sigan funcionando.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
When an SP requires both StepUp and an SRAM/SBS check, SBS may return an interrupt response with a nonce. EngineBlock stores that nonce and performs StepUp first. After StepUp returns, EngineBlock redirects the browser to SBS with an empty nonce query parameter instead of the nonce SBS issued. This may prevent SBS from resuming the interrupt flow.
In StepupAssertionConsumer , EngineBlock detects the stored SRAM step but passes the StepUp Gateway response to handleSramInterruptCallout() rather than the original response containing the SBS nonce.
Steps to reproduce
- Configure an SP to require StepUp and SRAM collaboration; enable eb.feature_enable_sram_interrupt .
- Configure SBS to return an interrupt response with a nonce, such as my-nonce .
- Log in through the IdP and complete StepUp.
- Inspect the browser's redirect to SBS.
Actual result
The SBS redirect contains an empty nonce, such as ?nonce= .
Expected result
The redirect contains the nonce from SBS's original interrupt response, such as ?nonce=my-nonce . The user can then complete the SBS step and continue through consent to the SP.
Acceptance criteria
• The SBS redirect after StepUp carries the original SBS nonce.
• A regression test asserts the nonce in the redirect and verifies the flow can continue after SBS.
• Existing StepUp-only, SBS-authorized, and SBS-interrupt-without-StepUp flows continue to work.
Technical hint: Pass the stored original response to handleSramInterruptCallout() in StepupAssertionConsumer . The existing combined-flow scenario does not assert the nonce, and its SBS mock ignores the redirect query string.
- Lenguaje dominante
- PHP
- Estrellas
- 17
- Forks
- 25
- Merge medio
- 2 d 13 h
- PR fusionados (30 d)
- 2
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de OpenConext/OpenConext-engineblock
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
OpenConext/OpenConext-engineblock#2122 · 4 comentarios ·
Los mantenedores suelen responder en 3 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
OpenConext/OpenConext-engineblock#2040 ·
Los mantenedores suelen responder en 3 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
OpenConext/OpenConext-engineblock#2015 ·
Los mantenedores suelen responder en 3 días
-
maintenance
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
OpenConext/OpenConext-engineblock#1960 · 2 comentarios ·
Los mantenedores suelen responder en 3 días
-
fix autocorrect in WAYF to prevent unwanted spelling correctionPosiblemente ocupada @kayjoosten la tomó hace 4 días. Abiertodiscovery UI
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
OpenConext/OpenConext-engineblock#1734 · 2 comentarios ·
Los mantenedores suelen responder en 3 días
Todos los issues de OpenConext/OpenConext-engineblock
Issues similares
-
maintenance
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
hawk-digital-environments/HAWKI#443 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 78/100
crazy-goat/rabbit-stream#799 ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
Code Quality
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Automattic/safe-publish#708 ·
Los mantenedores suelen responder en 1 día