Replies: 5 comments 13 replies
-
I'd suggest to use a recent release |
Beta Was this translation helpful? Give feedback.
-
I had constant problems with a pre 2.x.x. release with state cookies and Bad Request errors for clients (our servers were on CentOs/httpd and we migrated to Ubuntu/apache just to more easily make use of current releases of mod_auth_openidc). After upgrading, applying the suggestions listed here greatly reduced the number of Bad Requests we hear about (though it still happens sometimes and I've figured out why): https://github.com/zmartzone/mod_auth_openidc/wiki/Cookies In particular to use the config option |
Beta Was this translation helpful? Give feedback.
-
A question comes out. If I deleted the session cookie, and reopen the page to send a new request to server, will server validate the session first then bypass the request? the current the behavior seems not. (Chrome cached the html file so no request to Example config is:
|
Beta Was this translation helpful? Give feedback.
-
Looks like |
Beta Was this translation helpful? Give feedback.
-
Hi @zandbelt is there anyway to remove all state cookie when users get the session cookie? I feel sometimes it did but sometime not. |
Beta Was this translation helpful? Give feedback.
-
It is randomly happen and can be fixed by remove state_xxx cookie.
v1.8.8
Beta Was this translation helpful? Give feedback.
All reactions