<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>264263</bug_id>
          
          <creation_ts>2023-11-06 09:04:11 -0800</creation_ts>
          <short_desc>[GTK] libwebkit2gtk broke SAML auth on Linux</short_desc>
          <delta_ts>2023-11-06 09:22:09 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKitGTK</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>PC</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <dup_id>262777</dup_id>
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>Gtk</keywords>
          <priority>P3</priority>
          <bug_severity>Major</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sean">seanmi</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>bugs-noreply</cc>
    
    <cc>mcatanzaro</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1990190</commentid>
    <comment_count>0</comment_count>
    <who name="Sean">seanmi</who>
    <bug_when>2023-11-06 09:04:11 -0800</bug_when>
    <thetext>After upgrading to version 2.4.1 of libwebkit2gtk we see some embedded browser failures. At first, this seemed to be an IDP issue but we&apos;re getting reports of many IDPs(Duo, Okta) with the same errors. During testing, we see that the user attempts to log in via SAML to an IDP and the site just refreshes and nothing happens. In the console logs we see this being logged:

[Warning] [blocked] The page at
[IDP LOGIN URL...] &lt;IDP LOGIN URL...&gt;
was not allowed to display insecure content from
blob:https://cisco.login.duosecurity.com/5d947f3c-4c16-4067-867d-72149959feb1.
(login.js, line 2)


Downgrading seems to fix this issue. Were there any changes to these policies that we can handle differently? 

Please let me know if there is any further information I can add or reproduction steps you need.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1990191</commentid>
    <comment_count>1</comment_count>
    <who name="Michael Catanzaro">mcatanzaro</who>
    <bug_when>2023-11-06 09:15:43 -0800</bug_when>
    <thetext>Hi there, this is bug #262777. It will be fixed in 2.42.2, which is coming soon.

*** This bug has been marked as a duplicate of bug 262777 ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1990193</commentid>
    <comment_count>2</comment_count>
    <who name="Sean">seanmi</who>
    <bug_when>2023-11-06 09:18:40 -0800</bug_when>
    <thetext>What is the bug ID of the duplicate so I can take a look?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1990197</commentid>
    <comment_count>3</comment_count>
    <who name="Sean">seanmi</who>
    <bug_when>2023-11-06 09:22:09 -0800</bug_when>
    <thetext>(In reply to Sean from comment #2)
&gt; What is the bug ID of the duplicate so I can take a look?

Ignore this, didn&apos;t realized it linked</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>