fusionauth-issues icon indicating copy to clipboard operation
fusionauth-issues copied to clipboard

Can't disable SSO for passwordless flow

Open elliotdickison opened this issue 2 years ago • 4 comments

Can't disable SSO for passwordless flow

Description

Unchecking the "Keep me signed in" option has no effect in the passwordless flow - a SSO session is still created, cookies are saved to the browser, and FusionAuth remembers the user.

Affects versions

Tested on 1.45.1. Will upgrade and test again, but I'm not seeing any mention of this issue in release notes.

Steps to reproduce

  1. Enable passwordless login for an app
  2. Click "Send me a magic link", uncheck "Keep me signed in", and enter your email.
  3. Click the link in the email to sign in.
  4. Observe that an SSO session has been created in FusionAuth.

Expected behavior

I expect "Keep me signed in" to behave the same for the passwordless flow as it does for the password flow: no SSO session should be created and FusionAuth should not remember the user.

Platform

(Please complete the following information)

  • Device: Desktop
  • OS: macOS
  • Browser + version: Chromium: 116.0.5845.179
  • Database: PostgresSQL 15.2

Related

  • https://github.com/FusionAuth/fusionauth-issues/issues/2472
  • https://github.com/FusionAuth/fusionauth-issues/issues/2893

Community guidelines

All issues filed in this repository must abide by the FusionAuth community guidelines.

elliotdickison avatar Sep 12 '23 13:09 elliotdickison

@jobannon can you please attempt to recreate to confirm this is a bug?

robotdan avatar Sep 15 '23 20:09 robotdan

@robotdan I can reproduce and see the issue in the code. Working on a test and fix.

jobannon avatar Sep 21 '23 04:09 jobannon

Wonder if this is related to https://github.com/FusionAuth/fusionauth-issues/issues/2472

mooreds avatar Sep 21 '23 11:09 mooreds

Tracking this issue via https://github.com/FusionAuth/fusionauth-issues/issues/2472. It may not be the exact same issue, but the solution will likely be the same.

robotdan avatar Oct 11 '23 02:10 robotdan

I believe this has been resolved via https://github.com/FusionAuth/fusionauth-issues/issues/2893 in version 1.53.3

Please re-open if it is still an issue.

robotdan avatar Dec 04 '24 23:12 robotdan