Uploaded image for project: 'Identity Provider'
  1. Identity Provider
  2. IDP-482

Prevent repeated login attempts

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 3.2.0
    • Labels:
      None

      Description

      Copied from IdPv2 issues (https://issues.shibboleth.net/jira/browse/SIDP-617#comment-17688) on request from Scott:

      We recently debugged a case where many users got a Shibboleth error message after authenticating at the IdP. All we found is: In the Shibboleth IdP there were many "No login context available, unable to return to authentication engine" even though the users used the correct login links and they most certainly had at a valid session cookie just before they entered their credential. But there were no error messages.

      The cause of this seems to be that - due to many users logging in at the same time due to an online exam - the authentication and redirect back to the SP took several seconds. Probably the SP has not responded for several seconds after the click on the login button and the redirect but the login page of the IdP still was shown in the user's web browser.
      Therefore, some impatient users clicked again on the login button even though they already were authenticated by the IdP and their IdP login context already was destroyed by the IdP.

      To prevent this potential error, one simple workaround could be to disable the submit button on the login page after the form was submitted.
      This could be implemented and added to the default templates for v3 with something like:

      <button class="form-element form-button" type="submit" name="_eventId_proceed" onclick="this.disabled=true;this.innerHTML='Logging in, please wait...';">Login</button>

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              cantor.2@osu.edu Scott Cantor
              Reporter:
              wkiyxkscr4bax/2pq5dvxwse0ei=@https://aai-logon.switch.ch/idp/shibboleth Lukas Haemmerle
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - 1 hour
                  1h
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 30 minutes Time Not Required
                  30m