-
-
Notifications
You must be signed in to change notification settings - Fork 29
Issue 117 Sign In Redirected To The Wrong Address
Clicking Sign in with SSO sent the browser to the FreeITSM host itself instead of to the identity provider, and produced a 404.
Reported in issue #117 by Kristian Madsen, running a hand-written PHP identity provider behind IIS.
The cause turned out to be on the reporter's side - a reverse proxy rewriting outbound requests. That is worth saying plainly at the top, because the report arrived with a confident and specific accusation against FreeITSM which was wrong, and the way that was settled is the useful part of this page.
Changes shipped anyway as updates #1286, #1287 and #1288, commits 95c3fe95 and f575e24a.
An analyst clicks the SSO button on the login page. Instead of arriving at the identity provider's sign-in form, the browser lands on the FreeITSM installation's own address with the provider's path stuck on the end, and the web server answers 404.
Nothing on the screen mentions the identity provider. Every visible symptom points at FreeITSM.
The issue was written with the help of an AI assistant and stated that FreeITSM "overrides the provider's host with the local application domain."
No such code path exists. FreeITSM builds the authorization URL from one source and one only - the authorization_endpoint published in the provider's own discovery document at /.well-known/openid-configuration. It is used verbatim. Rewriting a provider's own address would itself be a bug, and a nasty one: it would break every legitimate provider that serves its endpoints from a different host than its issuer, which includes Microsoft Entra and Okta.
So the first job was not to argue but to look. The provider's discovery document is public, unauthenticated metadata - the same request the D003 diagnostic makes - and fetching it settled the question in one step:
authorization_endpoint : https://www.zodiacrp.dk/oidc/authorize
Absolute, correct, and pointing at the provider. Whatever was rewriting the address, it was not the discovery document and it was not us.
The reporter found it: Application Request Routing, the IIS reverse proxy module, was rewriting outbound requests when it had not been configured to.
That is why the symptom was so misleading. The address FreeITSM emitted was correct. The address the browser followed was not. Nothing inside the application could see the difference, and nothing it could log would have shown it.
The report described a real failure shape even though it misattributed it, and that shape is worth defending against:
A relative
Location:header is resolved by the browser against the current origin.
The OIDC specification requires authorization_endpoint to be an absolute URL, but a misconfigured provider can publish a bare path - /oidc/authorize. FreeITSM used the published value verbatim, so that went straight into:
header('Location: ' . $authUrl);The browser then resolves /oidc/authorize against the host it is currently on, which is the FreeITSM installation. The user lands on their own service desk, gets a 404, and nothing anywhere implicates the identity provider. It is indistinguishable from the ARR symptom, from the outside.
oidcDiscover() now refuses any of authorization_endpoint, token_endpoint or jwks_uri that is not an absolute http or https URL, and the error names the identity provider as the thing to fix and quotes the offending value.
The validator is deliberately not filter_var($url, FILTER_VALIDATE_URL):
function oidcIsAbsoluteHttpUrl(string $url): boolFILTER_VALIDATE_URL accepts javascript: and data: URLs. Those must never reach a browser redirect. A validation function that answers "is this a URL" is the wrong question when the real question is "is this safe to put in a Location: header".
D003 prints the health of a self-service SSO provider. Two things came out of using it on this issue.
The first: it reported each endpoint as present or absent. The one fact that decides where the browser goes was the one fact the tool would not state. It now prints the value of each endpoint, masked through maskGuids so an Entra tenant id does not leak into a pasted diagnostic.
The second is the more instructive. D003 compared the issuer typed into FreeITSM against the issuer in the discovery document and reported a mismatch as "this breaks login".
It does not. validateIdToken compares the token's iss claim against $disco['issuer'] - the provider's own declared value - not against the field typed into FreeITSM. So the commonest mismatch of all, www.example.com versus example.com, signs in perfectly well. A different host from the issuer is also entirely legitimate and is now reported as a note rather than a failure, because Entra and Okta both do it.
A diagnostic that names the wrong culprit costs somebody a day, which is precisely the disease this whole issue was about.
ποΈ schema Β· π read Β· βοΈ write Β· π₯οΈ UI Β· π§ͺ test
| π¨ | File | What changed |
|---|---|---|
| βοΈ | includes/oidc.php |
oidcDiscover() rejects non-absolute endpoints; new oidcIsAbsoluteHttpUrl()
|
| π | api/system/debug-tools/D003_selfservice_sso.php |
Prints endpoint values; issuer mismatch demoted from blocker to note; protocol shown and schema-checked |
| π§ͺ | tests/oidc-discovery.php |
27 assertions, mostly negative cases |
The mechanism was reproduced end to end rather than reasoned about. A directory under the web root served a deliberately malformed .well-known/openid-configuration, with a temporary auth_providers row pointing at it. With the guard disconnected the endpoint really does emit:
Location: /oidc/authorize?client_id=...
Both the fixture and the temporary row were removed afterwards.
The test was proved load-bearing by disconnecting the guard - 26 passing and 1 failing, then 27 passing when restored. A test that has never been seen to fail has not been shown to test anything.
- If SSO sends you to your own FreeITSM address, suspect the path between the browser and the provider before suspecting FreeITSM. A reverse proxy that rewrites outbound requests - IIS ARR, nginx
proxy_redirect, a load balancer - can do this invisibly. - If your provider publishes a relative endpoint, FreeITSM now refuses it by name at the point of discovery instead of bouncing you to a 404.
- Run D003 from System β Debug tools. It now prints the addresses it found, which is usually enough to see the answer without reading any code.
- The demo data import deleted real accounts - reported by the same person, immediately after this, and far more serious
- Single sign-on
- Setting up SSO with Keycloak
- The default password could not be changed - the same family: a relative address resolved against the wrong origin
FreeITSM β an open-source IT Service Management platform Β· github.com/edmozley/freeitsm Β· MIT licence
- Installation
- β° Scheduled tasks (cron jobs)
- Architecture
- π§ͺ Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- π Date & Time Formats
- Theming & Dark Mode
- ποΈ Recent β getting back to what you were doing
- β¨οΈ Command palette (βK)
- π Searching inside tickets
- π Attached documents
-
MobileβFriendly
- β³ π« Mobile: Tickets
- β³ π» Mobile: Assets
- β³ π Mobile: Calendar
- β³ π Mobile: Knowledge
- β³ π¦ Mobile: Service Status
- β³ πΌ Mobile: Watchtower
- β³ π§© Mobile: Problem Management
- β³ π Mobile: Change Management
- β³ πΏ Mobile: Software
- β³ β Mobile: Tasks
- β³ π Mobile: Forms
- β³ π Mobile: Contracts
- β³ π Mobile: Domains
- β³ π Mobile: People
- β³ π Mobile: LMS
- β³ πΊοΈ Mobile: CMDB
- β³ πΊοΈ Mobile: Network Mapper
- β³ π§ Mobile: Process Mapper
- β³ βοΈ Mobile: Workflow
- β³ π₯οΈ Mobile: System
- β³ π Mobile: Reporting
- β³ π Mobile: System Wiki
- β³ π Mobile: Self-Service Portal
- β³ π§° Mobile: Techniques & Tricks
-
Security
- Layer 1 β which modules you can enter
- β³ π§© Module Access Control
- β³ π οΈ Module Access β Developer Guide
- Layer 2 β what you can administer
- β³ π Roles & Permissions
- β³ π οΈ Roles β Developer Guide
- β³ π€ Why capabilities are constants
- Layer 3 β the System module
- β³ π Admin Access Control
- Hardening
- β³ π Security review response 2026-08
- β³ π‘οΈ Security hardening 2026-08
- β³ π οΈ Security hardening 2026-08 β Developer Guide
- β³ π‘οΈ Round three β plain English
- β³ π οΈ Round three β Developer Guide
- β³ π‘οΈ CSRF protection (S4) β Developer Guide
- Single Sign-On (SSO)
- ποΈ LDAP & Active Directory
- π CardDAV contact sync
- Browser Extension
- API Reference
-
π REST API β how it works
- β³ π« REST API: Tickets
- β³ π» REST API: Assets
- β³ π΄ REST API: Problems
- β³ π REST API: Changes
- β³ π REST API: Knowledge
- β³ β REST API: Tasks
- β³ ποΈ REST API: CMDB
- β³ π REST API: Contracts
- β³ ποΈ REST API: Calendar
- β³ πΏ REST API: Software
- β³ π REST API: Domains
- β³ π¦ REST API: Service Status
- β³ βοΈ REST API: Morning Checks
- β³ π REST API: Forms
- β³ βοΈ REST API: Workflow
- β³ π·οΈ REST API: Cost centres
- β³ πΊοΈ REST API: Network Mapper
- β³ π§ Using the API docs page
- β³ π OpenAPI specification
- β³ β OpenAPI: kept correct
- β³ π οΈ Maintaining the catalogue
- Watchtower
-
Tickets
- β³ π Rota copy and paste β Developer Deep Dive
- β³ β Checklists & SOPs
- β³ βοΈ Mandatory fields
- β³ π·οΈ Ticket categories
- β³ π₯ Assigning tickets to a team, and escalation
- β³ π’ One board across every company
- β³ Mailbox Authentication
- β³ π€ Email send log
- β³ Basic IMAP mailboxes
- β³ Email rendering & images
- β³ SLA Management
- β³ WhatsApp channel
-
β³
βοΈ Telegram channel - β³ β CSAT company scope and filters β Developer Guide
- β³ π₯ Microsoft Teams channel
- β³ π¨οΈ Mattermost channel
- β³ π¬ Web chat channel
- β³ π£ Slack channel
- β³ π Linking tickets
- β³ β Record previews
- β³ π Ticket notes: internal or shared
- β³ ποΈ Canned responses
- β³ βοΈ Limiting replies to particular senders
- β³ π¨ Telling the analyst a ticket is theirs
- β³ βοΈ Email signatures
- β³ π The public web address
- β³ π’ Ticket numbering
- β³ π Raising a ticket for someone else
- β³ π Merging tickets
- β³ π Confidential tickets
- β³ π₯ Portal managers
- β³ π Who has seen a ticket
- β³ π Reading long tickets
- β³ β Splitting tickets
- β³ β Selecting several tickets
- β³ ποΈ The folder pane
- β³ π½ Just my tickets, or no closed ones
- β³ π οΈ Snoozing tickets β Developer Guide
- β³ π₯ Collision detection
- β³ β±οΈ Time tracking
- β³ π Scheduled work in your own calendar
- Problem Management
- Tasks
-
Assets
- β³ π’ Moving an asset between companies
- β³ π Shared asset locations
- β³ π§βπΌ Assigning assets to analysts
- β³ π Warranty and lease alerts
- β³ π Saved table views
- β³ π¨οΈ Recording anything, and importing it
- β³ π·οΈ QR asset labels
- β³ π Who holds what, and handover documents
- β³ π₯οΈ The inventory agent (PowerShell)
- β³ ποΈ Proxmox VE servers
- β³ βοΈ VMware Cloud Director servers
- β³ π Linking equipment to tickets
- β³ βοΈ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- β³ π¨ The form designer β Developer Guide
- β³ π Layout & the grid β Developer Guide
- β³ ποΈ Collections β grouping submissions
- β³ π Submissions as PDFs
- β³ β‘ What happens next β a form's own actions
- β³ π οΈ Sections & conditional logic β Developer Guide
- β³ π οΈ Lookup fields β Developer Guide
- β³ π‘οΈ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- π Notifications
- π¨ War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- β³ π Progress tracker
- β³ Concepts & vocabulary
- β³ Email routing & mailboxes
- β³ Settings: global vs per-company
- β³ Users & self-service
- β³ Staff cross-company access
- β³ π’ One board across every company
- β³ Worked examples
- β³ Pitfalls & gotchas
- β³ Scope: what it's for
- β³ π οΈ Developer Guide (make a module multi-company)
- β³ ποΈ Case study: CMDB (a linked graph)
- β³ π§ͺ Test harness (prove it's isolated)
- What this is
-
π Bugs resolved
- β³ πΌοΈ Logo and courses broke on Apache with PHP-FPM
- β³ π’ Chat tickets ignored your ticket numbering
- β³ π Dates shown as a dash, or in server time
- β³ π Assets β Users showed people from other companies
- β³ π Restricted analysts could read other modules' data
- β³ πΌοΈ Replies with a picture in the thread failed to send
- β³ π Reply attachments never reached the customer
- β³ π οΈ Outbound email attachments β Developer Guide
- β³ π A global SSO provider was missing from the portal
- β³ π Behind a proxy, the SSO redirect said http
- β³ βοΈ The portal tagline moved when you saved it
- β³ π¨ The portal settings screen forgot what you saved
- β³ π‘οΈ The approvals inbox said "Error" and nothing else
- β³ π A table's answers were missing from the PDF
- β³ β A single-select column let you tick every option
- β³ π The portal ignored a form's field widths
- β³ π The tasks board stopped taking clicks
- β³ ποΈ #121 The index list is out of date after upgrading
- β³ π #133 The calendar subscription was empty
- β³ π #131 Tasks always reopened on the board
- β³ π₯ #129 Every page returned HTTP 500 after upgrading
- β³ π³ #127 A PHP warning above the System page
- β³ π #126 Notes stamped with the server's clock
- β³ π Storing every date in UTC
- β³ πͺ The portal was down for everyone signed in
- β³ βοΈ #120 Workflow notes could never be written
- β³ βοΈ #123 Three errors when running Database Verification
- β³ π #122 The description box was a stub in the corner
- β³ π£ Demo data deleted real accounts
- β³ π #117 Sign-in redirected to the wrong address
- β³ π¨ #108 The priority dot was invisible
- β³ β±οΈ #116 Time logged from the right-click menu
- β³ π #114 API keys refused by our own guard
- β³ ποΈ #110 Assigning a task told nobody
- β³ πͺ #107 Signed out while still working
- β³ π #103 "Share with Requester" reached nobody
- β³ π #102 Search found nothing for hyphens
- β³ πͺ #101 Source code editor opened behind
- β³ βοΈ #88 Subtasks could not be ticked off
- β³ π» #84 Asset deep link selected nothing
- β³ π« #79 A new ticket arrived with no status
- β³ π§ #79 A ticket from email did not say so
- β³ π #78 Bell opened to nothing
- β³ π¬ #77 Mail only collected from Inbox
- β³ π #74 The default password could not be changed
- β³ π¦ #70 Renaming an impact level
- β³ π€ #67 App-only mailboxes could not send
- β³ π #45 Verify only ever worked for Microsoft
- β³ π #45 IMAP reported as not authenticated
- β³ βοΈ An email template stopped escaping itself
- β³ π The portal dashboard showed the wrong time
- β³ π’ The folder said 99 and the list showed 96