<bitmap[m]> "sorry for the delay, I've tested..." <- just made some changes to the google side, could you please try again in a fresh session?
2025-04-21 11100, 2025
julian45[m]
(misread the field names in google's config and realized I was telling it to send saml auth requests to a generic page, rather than the endpoint on the saml proxy meant for consuming the request — that's what i get for trying to mess with saml at night, lol)
2025-04-21 11152, 2025
bitmap[m]
julian45[m]: it's different now, at least :) but when I log in from Google it redirects me to a plain text page with `https://accounts.google.com/samlrp/<random string>` visible and gets stuck there
2025-04-21 11133, 2025
kepstinbrainz has quit
2025-04-21 11135, 2025
bitmap[m]
(stuck on the /kanidm_saml-google_oidc/sso/redirect page, that is. also, this page returns a 500 status code)
2025-04-21 11104, 2025
julian45[m]
f#$(king SAML weirdness... there are two possible types of request that an SP can send to start a saml auth request and the saml proxy has two different endpoints for them... i guessed one, maybe it was the other (i'll also check the proxy's logs in a bit
2025-04-21 11103, 2025
julian45[m]
made another change (trying the other endpoint), please give it a shot in a few
2025-04-21 11150, 2025
vardhan_ has quit
2025-04-21 11124, 2025
vardhan joined the channel
2025-04-21 11144, 2025
vardhan has quit
2025-04-21 11106, 2025
void09 has quit
2025-04-21 11156, 2025
vardhan joined the channel
2025-04-21 11150, 2025
void09 joined the channel
2025-04-21 11114, 2025
vardhan has quit
2025-04-21 11149, 2025
allen has quit
2025-04-21 11123, 2025
vardhan joined the channel
2025-04-21 11156, 2025
vardhan has quit
2025-04-21 11149, 2025
bitmap[m]
<julian45[m]> "made another change (trying..." <- getting the same issue
2025-04-21 11129, 2025
bitmap[m]
(should the /kanidm_saml-google_oidc/sso/post endpoint have changed? because I still end up there)
2025-04-21 11112, 2025
julian45[m]
<bitmap[m]> "(should the /kanidm_saml-google..." <- i expected the change you seem to have seen (`post` instead of `redirect`) but not the same behavior :/ can you please send me a SAML-tracer export with another attempt?
2025-04-21 11106, 2025
bitmap[m]
sent, hope it helps!
2025-04-21 11109, 2025
julian45[m]
if no further fiddling works, luckily google has another SSO option (OIDC) in beta that should be a good deal less fiddly but we do need saml working for at least one or two other services :/
2025-04-21 11114, 2025
BrainzGit
[bookbrainz-site] 14dependabot[bot] opened pull request #1165 (03master…dependabot/npm_and_yarn/elastic/elasticsearch-9.0.0): chore(deps): bump @elastic/elasticsearch from 5.6.22 to 9.0.0 https://github.com/metabrainz/bookbrainz-site/pul…
2025-04-21 11116, 2025
BrainzGit
[bookbrainz-site] 14dependabot[bot] closed pull request #1155 (03master…dependabot/npm_and_yarn/elastic/elasticsearch-8.17.1): chore(deps): bump @elastic/elasticsearch from 5.6.22 to 8.17.1 https://github.com/metabrainz/bookbrainz-site/pul…