<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[SAML CSRF token issue]]></title><description><![CDATA[<p dir="auto">Hi!</p>
<p dir="auto">We have a setup in which FusionAuth is acting as SAML Idp, using hosted login pages.</p>
<p dir="auto">Now if I try to login to the connected application through the /samlv2/login url in browser, it redirects to /oauth2/authorize. So far so good.</p>
<p dir="auto">But, If I keep this browser tab open (tab A), then open a new tab (tab B) and also start the authorization process there, the <em>saml.csrf</em> cookie is now changed for tab A, which I think is the reason why if you try to finish the authorization process in tab A, you get a "OAuth return is missing a valid CSRF token." error.</p>
<p dir="auto">Is there a way to avoid this? Or is it a consecuence of the CSRF system?</p>
<p dir="auto">Additional information:</p>
<ul>
<li>Tested on Chrome 137.0.7151.120</li>
<li>FusionAuth 1.57.0</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/topic/3009/saml-csrf-token-issue</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Jul 2026 00:30:33 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3009.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 30 Jun 2025 09:17:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to SAML CSRF token issue on Fri, 11 Jul 2025 10:06:33 GMT]]></title><description><![CDATA[<p dir="auto"><a class="mention plugin-mentions-user plugin-mentions-a" href="https://fusionauth.io/community/forum/uid/2507">@mark-robustelli</a><br />
Thanks I just did that.<br />
<a href="https://github.com/FusionAuth/fusionauth-issues/issues/3113" rel="nofollow ugc">https://github.com/FusionAuth/fusionauth-issues/issues/3113</a></p>
]]></description><link>https://fusionauth.io/community/forum/post/8246</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8246</guid><dc:creator><![CDATA[joseantonio]]></dc:creator><pubDate>Fri, 11 Jul 2025 10:06:33 GMT</pubDate></item><item><title><![CDATA[Reply to SAML CSRF token issue on Tue, 01 Jul 2025 14:08:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="mention plugin-mentions-user plugin-mentions-a" href="https://fusionauth.io/community/forum/uid/516">@joseantonio</a> Ah OK. That makes sense. I couldn't find much detail on how the saml.csrf cookie works. It does seem plausible that when a new window is open that a value could change that could be causing this problem. If it is causing you problems, it may be work opening a new <a href="https://github.com/FusionAuth/fusionauth-issues/issues" rel="nofollow ugc">issue</a>.</p>
]]></description><link>https://fusionauth.io/community/forum/post/8225</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8225</guid><dc:creator><![CDATA[mark.robustelli]]></dc:creator><pubDate>Tue, 01 Jul 2025 14:08:05 GMT</pubDate></item><item><title><![CDATA[Reply to SAML CSRF token issue on Mon, 30 Jun 2025 16:16:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="mention plugin-mentions-user plugin-mentions-a" href="https://fusionauth.io/community/forum/uid/2507">@mark-robustelli</a></p>
<p dir="auto">Thank you for the quick reply.</p>
<p dir="auto">By "Also start the authorization process there?" I mean manually open a new tab for my application and clicking on "Login" which redirects to "/oauth2/authorize". So the same login process initiated twice in different tabs, then introducing login credentials on the first one.</p>
<p dir="auto">The debug doesn't shed any light I'm afraid. The problem seems to be the "saml.csrf" cookie changing it's value across tabs.</p>
]]></description><link>https://fusionauth.io/community/forum/post/8224</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8224</guid><dc:creator><![CDATA[joseantonio]]></dc:creator><pubDate>Mon, 30 Jun 2025 16:16:40 GMT</pubDate></item><item><title><![CDATA[Reply to SAML CSRF token issue on Mon, 30 Jun 2025 15:12:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="mention plugin-mentions-user plugin-mentions-a" href="https://fusionauth.io/community/forum/uid/516">@joseantonio</a> said in <a href="/community/forum/post/8222">SAML CSRF token issue</a>:</p>
<blockquote>
<p dir="auto">also start the authorization process there</p>
</blockquote>
<p dir="auto">What do you mean by "Also start the authorization process there?" Manually open a new tab (tab B) and paste in the URL " /oauth2/authorize"?</p>
<p dir="auto">If you enable debugging on the SAML tab for the Application in FusionAuth, do the logs indicate anything interesting?</p>
]]></description><link>https://fusionauth.io/community/forum/post/8223</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8223</guid><dc:creator><![CDATA[mark.robustelli]]></dc:creator><pubDate>Mon, 30 Jun 2025 15:12:37 GMT</pubDate></item></channel></rss>