Hi,

We just came across a problem leading to this line in CAS logs:


*Invalid cookie. Required fields are missing*After investigations, it turns 
out that when using Ecosia as a browser to perform OIDC Auth Flow (PKCE), 
CAS fails to retrieve distincts values from cookie (Value / IP / 
User-Agent) because the parsing splits on* '@'* and expects exactly *3 
values* as a result (verified in current code on github)

In our testings, User-Agent from Ecosia appears as
* [email protected]*, adding an *'@'* to the mix. Splitting gives 4 
values, throwing an exception.

Has anyone encountered this problem yet and did you find a solution ?

I don't know if 2 '@' in the cookie is an assumption and needs to be fixed 
in CAS based on this example, or if it's protocol and Ecosia is in the 
wrong..

Thanks,
Damien

-- 
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/548a888f-0ccc-410f-b8de-4aa1a1d2c380n%40apereo.org.

Reply via email to