From: Krzysztof B. <kb...@un...> - 2021-08-30 09:00:45
|
Hi Sander, W dniu 23.08.2021 o 09:30, Krzysztof Benedyczak pisze: > W dniu 23.08.2021 o 07:29, Sander Apweiler pisze: >> Good morning Krzysztof, >> I'm not sure for all, but atleast for some I know what they did: >> - Browse to /home endpoint >> - Select external IdP >> - Authenticate at external IdP >> - Got register pop-up >> - Register account >> >> I guess, but I have no hints for it, that some other users went to SAML >> or OAuth endpoint instead of userhome endpoint. > > OK, so that's the unknown remote user flow. We will re-check that for > any regressions. I've retested that scenario manually and it seems to block such situation as before. I.e. user who has no remote attribute, and this attribute is required in the form as a remote provided, can't even see the form. Maybe you have hit some edge case here? Can you please check the exact data that came from the remote IdP (or more precisely - to what it was mapped by the input profile) and then compare it against form config? Cheers, Krzysztof |