Ramsons (R2 2024) Critical Service Patch #4 (OKAPI)

Ramsons (R2 2024) Critical Service Patch #4 (OKAPI)

Released at july 1

Approval Log

key summary priority CSP Request Details CSP Approved
Loading...
Refresh

Key

Summary

CSP Request Details

Key

Summary

CSP Request Details

MODLOGSAML-209

Increase SSO maximumAuthenticationLifetime from 5 to 8 hours

Released as mod-login-saml 2.9.4.

This breaking change in the Single Sign On (SSO) login lifetime will likely violate the security policy of some institutions, in this case downgrade to mod-login-saml 2.9.3.

  1. Describe issue impact on business
    Institutions need to run mod-login-saml 2.10.1, the Sunflower version, in their Ramsons environment, to mitigate the logout problem MODLOGSAML-208. Impact on business: Institutions fear that the Sunflower version is not compatible with Ramsons resulting in bad feelings.

  2. What institutions are affected? (field “Affected Institutions” in Jira to be populated)
    Institutions that run Ramsons, and that have a SSO IdP with an authentication lifetime longer than 5 hours. Chalmers and Massey.

  3. What is the workaround if exists?
    a) Use mod-login-saml 2.10.1 and trust developers that it is fully compatible with Ramsons.
    or
    b) Use workarounds explained on MODLOGSAML-208: 500 server error occurring when trying to login via SSOClosed

  4. What areas will be impacted by fix (i.e. what areas need to be retested)
    Login with SSO.

  5. Brief explanation of technical implementation and the level of effort (in workdays) and technical risk (low/medium/high)
    Bump maximumAuthenticationLifetime, less than a workday effort, very low technical risk.

  6. Brief explanation of testing required and level of effort (in workdays). Provide test plan agreed with by QA Manager and PO.
    Login with SSO.

  7. What is the roll back plan in case the fix does not work?
    Use previous version.

Tickets list

key summary type assignee priority resolution reporter Development Team
Loading...
Refresh

Modules list

Release tag

https://github.com/folio-org/platform-complete/tree/R2-2024-csp-4