Skip to content

1.0.17 — a login that waits for you

Latest

Choose a tag to compare

@guFalcon guFalcon released this 19 Sep 10:41

Logging in could stop working, permanently, on a realm whose sessions are configured a certain way — and it stopped before you had typed anything. The browser opened on the sign-in page, the status bar said Logging in since …, and the plugin immediately reported that nothing came back. When the sign-in did complete, the answer was a login already given up on. Both messages pointed at the browser, which had done nothing wrong.

The plugin was giving a login in progress as long as the realm's last token response said a refresh token would live. That figure is not a measure of how long a person takes at a login page — near the end of a session Keycloak answers it with the seconds that are left, and one installation ended up storing 1. Every login was then over on the first tick after the browser opened, and nothing could overwrite the figure, because only a successful login would have.

A login now gets ten minutes, decided by the plugin and by nothing else: enough for a password, a second factor, and a moment of finding the phone the second factor is on.

If logging in had stopped working for you, updating is the whole fix. There is nothing to reset and nothing to configure — the stored figure is no longer consulted at all.

Also in this release: with Debug logging switched on, the login itself now shows up in the developer console — a login starting and the deadline it was given, a login ending at that deadline, and a callback arriving with what became of it. Enough to read the next problem of this shape off the log instead of reconstructing it. The values that tie a callback to its login are truncated, so a log stays safe to send to somebody while a login may still be in flight.