Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Sidedoor no longer working after Australia upgrade

LVdV
Tera Expert

Hi all

 

Our sidedoor no longer works immediately after our Australia upgrade (patch6). When trying to access it, the user gets redirected to the single sign-on provider.

 

Thanks for any help in this

Lorenz

 

 

1 ACCEPTED SOLUTION

Joni V B
Kilo Sage

Hi Lorenz,

 

We recently encountered the same issue after upgrading to Australia.
You can add a new system property 'glide.additional_exempted_redirecting_uris'

In that property add your sidedoor url (eg. /sidedoor.do), this will prevent the SSO redirection.

 

The knowledge article can be found here:

https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3071161

 

Full content for people without access:

Description

After upgrading to Australia, when SSO is enabled, the side_door.do page no longer works to allow local logins.

Previously, in Zurich, even with auto-redirect enabled, accessing /side_door.do still allowed users to access the local login page.

In an OOB instance with:
* SSO enabled
* Auto-redirect enabled
* ACR disabled

using /side_door.do displayed the local login page (similar to login.do) in the Zurich release.

Steps to Reproduce

 

An instance is affected if:

- They are on Australia.
- SSO / external authentication is enabled.
- SSO auto-redirect is enabled, so normal unauthenticated access is redirected to the identity provider.
- They rely on /side_door.do to bypass SSO and reach the local login page.
- /side_door.do is not already exempted through glide.additional_exempted_redirecting_uris.
- The user is unauthenticated or using a guest session when accessing side_door.do.

In these conditions, the guest session carrying the side_door marker can be invalidated before navpage.do uses it. When that marker is lost, the user falls back into the normal SSO redirect path instead of reaching the local login page.

Workaround

For Australia instances where SSO auto-redirect is enabled and /side_door.do no longer reaches the local login page, add /side_door.do to glide.additional_exempted_redirecting_uris. This prevents the guest session created by side_door.do from being invalidated before the redirect to navpage.do can consume the side_door session marker.


Related Problem: PRB2029440

View solution in original post

2 REPLIES 2

Joni V B
Kilo Sage

Hi Lorenz,

 

We recently encountered the same issue after upgrading to Australia.
You can add a new system property 'glide.additional_exempted_redirecting_uris'

In that property add your sidedoor url (eg. /sidedoor.do), this will prevent the SSO redirection.

 

The knowledge article can be found here:

https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3071161

 

Full content for people without access:

Description

After upgrading to Australia, when SSO is enabled, the side_door.do page no longer works to allow local logins.

Previously, in Zurich, even with auto-redirect enabled, accessing /side_door.do still allowed users to access the local login page.

In an OOB instance with:
* SSO enabled
* Auto-redirect enabled
* ACR disabled

using /side_door.do displayed the local login page (similar to login.do) in the Zurich release.

Steps to Reproduce

 

An instance is affected if:

- They are on Australia.
- SSO / external authentication is enabled.
- SSO auto-redirect is enabled, so normal unauthenticated access is redirected to the identity provider.
- They rely on /side_door.do to bypass SSO and reach the local login page.
- /side_door.do is not already exempted through glide.additional_exempted_redirecting_uris.
- The user is unauthenticated or using a guest session when accessing side_door.do.

In these conditions, the guest session carrying the side_door marker can be invalidated before navpage.do uses it. When that marker is lost, the user falls back into the normal SSO redirect path instead of reaching the local login page.

Workaround

For Australia instances where SSO auto-redirect is enabled and /side_door.do no longer reaches the local login page, add /side_door.do to glide.additional_exempted_redirecting_uris. This prevents the guest session created by side_door.do from being invalidated before the redirect to navpage.do can consume the side_door session marker.


Related Problem: PRB2029440

 That did the trick for us. Thanks, Joni!