Hi Till,
The problem is most likely that you need to wipe your cookies, because the existing CSRF cookie is stored as "Strict", so you need to delete it to make it "Lax" again.
a proper fix has now been uploaded to SVN. Now there are two CSRF cookies, one for AJAX and one for OAuth.
At my test system, it seems to work (started OAuth in Chrome Incognito mode), I can login to OIDplus, but for some reason I get a "HTTP 500" on the 2-factor-authentication screen on my iPhone ?
I will investigate it
Please let mek now if it now works for you, and if you 2-factor-authentication works correctly
Regards,
Daniel
|