Does SSO require a refer from the sso_login url?


(George Kushnir) #1

I’m trying to login a user after forwarding from sso using a silent GET request, which seems to be failing.

Does the login require it be referred DIRECTLY from the specified SSO login? I believe it does from my testing (or I am missing something crucial). If so, is there a way to change this or work around it?


(David Taylor) #2

What do you mean by this? Are you doing a GET request to discourse SSO in JavaScript?


(George Kushnir) #3

I am redirecting the SSO login page (after authenticating) to another page, which then takes the passed SSO data and calls the login URL via JS, but this does not work, despite not throwing an error.