self-hosted icon indicating copy to clipboard operation
self-hosted copied to clipboard

SSO (ADFS) with 2FA broken

Open 13werwolf13 opened this issue 1 year ago • 6 comments

Environment

self-hosted (https://develop.sentry.dev/self-hosted/)

Steps to Reproduce

  1. install self-hosted sentry
  2. add ADFS SSO
  3. add 2FA to user accounts

Expected Result

after login write totp key & work

Actual Result

2FA works for some users, for others it doesn’t (it asks for a key, but regardless of its correctness, it simply doesn’t login into sentry)

Product Area

Sign In

Link

No response

DSN

No response

Version

23.6.1

13werwolf13 avatar Jan 09 '24 07:01 13werwolf13

Assigning to @getsentry/support for routing ⏲️

getsantry[bot] avatar Jan 09 '24 07:01 getsantry[bot]

Do you have any server logs (from the web container) when these log ins fail? Generally, you'll be looking for a 400 or 403 error.

azaslavsky avatar Jan 11 '24 17:01 azaslavsky

This issue has gone three weeks without activity. In another week, I will close it.

But! If you comment or otherwise update it, I will reset the clock, and if you remove the label Waiting for: Community, I will leave it alone ... forever!


"A weed is but an unloved flower." ― Ella Wheeler Wilcox 🥀

getsantry[bot] avatar Feb 02 '24 08:02 getsantry[bot]

Do you have any server logs (from the web container) when these log ins fail? Generally, you'll be looking for a 400 or 403 error.

I apologize for the long wait. I was sure I had already answered.

so, at the time of the problem I don’t see errors 40* in the logs

13werwolf13 avatar Feb 02 '24 08:02 13werwolf13

Do you see anything suspicious in the web logs at all? It's odd that it would fail to log users in without leaving any breadcrumbs.

azaslavsky avatar Feb 06 '24 00:02 azaslavsky

Do you see anything suspicious in the web logs at all? It's odd that it would fail to log users in without leaving any breadcrumbs.

We will try to repeat the problem on a test bench so as not to experiment on a production instance. I'll come back later with an example log.

13werwolf13 avatar Feb 06 '24 04:02 13werwolf13

This issue has gone three weeks without activity. In another week, I will close it.

But! If you comment or otherwise update it, I will reset the clock, and if you remove the label Waiting for: Community, I will leave it alone ... forever!


"A weed is but an unloved flower." ― Ella Wheeler Wilcox 🥀

getsantry[bot] avatar Feb 28 '24 08:02 getsantry[bot]