Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-1945

Make Crowd's cookie domain validation consistent with RFC 6265

    • Icon: Suggestion Suggestion
    • Resolution: Fixed
    • 2.5
    • None
    • None
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Currently Crowd allows admins to set a single sub-domain level only for the Cookie pattern.

      Example:
      URL Domain: abc.xyz.example.com
      SSO Domain Allowed: .xyz.example.com
      SSO Domain Not Allowed: .example.com (it would reach two sub-domain levels)

      If the browsers don't respect rfc2965, there is an opportunity to allow the definition of .example.com as the cookie pattern and support many subdomains for SSO.

      Currently the code defined at class SSOUtils blocks this behavior.

      • This problem is affecting Crowd 2.4.0

            [CWD-1945] Make Crowd's cookie domain validation consistent with RFC 6265

            Katherine Yabut made changes -
            Workflow Original: JAC Suggestion Workflow [ 3363821 ] New: JAC Suggestion Workflow 3 [ 3628010 ]
            Status Original: RESOLVED [ 5 ] New: Closed [ 6 ]
            Monique Khairuliana (Inactive) made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 - restricted [ 1509991 ] New: JAC Suggestion Workflow [ 3363821 ]
            Issue Type Original: Task [ 3 ] New: Suggestion [ 10000 ]
            Owen made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 [ 1392652 ] New: Simplified Crowd Development Workflow v2 - restricted [ 1509991 ]
            Owen made changes -
            Workflow Original: Crowd Development Workflow v2 [ 273683 ] New: Simplified Crowd Development Workflow v2 [ 1392652 ]
            joe made changes -
            Link New: This issue supersedes CWD-1938 [ CWD-1938 ]
            joe made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Technical Review [ 10028 ] New: Resolved [ 5 ]
            joe made changes -
            Status Original: In Progress [ 3 ] New: Technical Review [ 10028 ]
            joe made changes -
            Status Original: Open [ 1 ] New: In Progress [ 3 ]
            joe made changes -
            Fix Version/s New: 2.5 [ 22894 ]
            joe made changes -
            Assignee New: joe [ jwalton ]

              jwalton joe
              rbattaglin Renan Battaglin
              Votes:
              3 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: