# Sporadic DiscourseSSO login issues with expired nonce

**URL:** <https://meta.discourse.org/t/sporadic-discoursesso-login-issues-with-expired-nonce/224441>\
**Category:** SSO\
**Created:** [April 15, 2022, 9:01pm UTC](https://meta.discourse.org/t/sporadic-discoursesso-login-issues-with-expired-nonce/224441 "2022-04-15T21:01:48Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![aarsaa](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@aarsaa](https://meta.discourse.org/u/aarsaa)\
**Post date:** [April 15, 2022, 9:01pm UTC](https://meta.discourse.org/t/sporadic-discoursesso-login-issues-with-expired-nonce/224441/1 "2022-04-15T21:01:48Z")

</div>

We use DiscourseSSO and sporadically users run into login issues (similar to [Sporadic issue wp-discourse/SSO: Nonce has already expired](https://meta.discourse.org/t/sporadic-issue-wp-discourse-sso-nonce-has-already-expired/94353)). I was trying to debug this by adding some extra logging and luckily ran into the issue after a couple of days. To be clear, login works most of the times, just that sporadically (may be for 5 mins a day) users run into login issues.

We use subfolder setup on multi-node cluster, using external shared DB and Redis if that makes any difference. There are two failing scenarios:

1. Nonce expired  
When the user is redirected to /session/sso\_login, SessionController does not get session\_id in the session and thus is not able to lookup the nonce. I tried logging the session (`Rails.logger.warn("Verbose SSO log: Session #{session.keys.map {|key| [key, session[key]].join('=')}.join(',')}")`) and it printed empty session. I verified that the browser is sending “_\_forum\_session_” cookie as received in the previous request and the cookie is logged on the server if logging in SessionController (`Rails.logger.warn("Verbose SSO log: Cookies #{cookies.map {|cookie| cookie.join('=')}.join(',')}")`).

2. Login completes but the user gets Login error on the screen  
When the user is redirected to /session/sso\_login, SessionController is able to verify SSO data and log the user in (I see `Verbose SSO log: User was logged on user5` in the logs). But when it redirects the user to /forums/latest, user sees an error on the screen. I noticed that in the working flow this action clears/returns-empty “_cn_” cookie but in the failing scenario, it just updates and returns “_\_t_” cookie. My guess is this scenario might also be related to missing session data.

If we wait for 5 mins or so and try again, then everything starts working fine again.

I have not tested if all users hitting the site at that time run into the issue or not, but I have been told anecdotally that multiple users ran into it once on our instance.

---

_[View the full topic](https://meta.discourse.org/t/sporadic-discoursesso-login-issues-with-expired-nonce/224441)._
