Fix SAML Client login flow on Apple devices

Because the redirect from the SAML/SSO endpoint is a POST the lax/strict
cookies are not properly send.

Note that it is not strictly requried on this endpoint as we do not need
the remember me data. Only the real session info is enough. The endpoint
is also already protected by a state token.

Signed-off-by: Roeland Jago Douma <roeland@famdouma.nl>
This commit is contained in:
Roeland Jago Douma 2018-12-17 12:50:32 +01:00 committed by Backportbot
parent 107e983da0
commit 359e4d8c0c
1 changed files with 1 additions and 0 deletions

View File

@ -207,6 +207,7 @@ class ClientFlowLoginController extends Controller {
/** /**
* @NoAdminRequired * @NoAdminRequired
* @NoCSRFRequired * @NoCSRFRequired
* @NoSameSiteCookieRequired
* @UseSession * @UseSession
* *
* @param string $stateToken * @param string $stateToken