381 Results
Best practice for Visitor Landing Page? (hiding components for anonymous users)
We're all logging on through SSO. But, we'd like the pre-SSO-sign-on landing page to be simple w/ a message like "hey, sign on using SSO to get started..." How can I hide a bunch of c...Solved333Views
Sign in to react to this post2Comments
- AbhishekGu3 years agoKhoros Alumni (Retired)
Hello keithkelly,
You can use following IF tag to hide components for anonymous users<#if !user.anonymous>
// Write code here which will not display to anonymous users
</#if>Sign in to react to this post
Free Marker: Any way to know if MyProfilePage was saved.
Hi There... I'm fairly sure I can do a lot of what I want using javascript. However, if possible I rather use Free Marker. Is it possible to know that the MyProfilePage was saved (as when t...Solved546Views
Sign in to react to this post8Comments
- AdamT15 years agoLithium Alumni (Retired)
My apologies.
You'll need to reference the results as so:
<#if activity.results.name.UserUpdated??> ... </#if>
Sorry for the confusion!
Sign in to react to this post
Why SSO Cookie was not written into response when using firefox browser?
We use Lithium SSO in our product. When users log into the website, we will call LithiumSSOClient.writeLithiumCookie() to write the SSO Cookie. When I use firefox to log into our website, I coul...Solved241Views
Sign in to react to this post1Comment
- DougS11 years agoKhoros Alumni (Retired)
When an SSO cookie is processed, Lithium tries to delete the cookie and replace it with a cookie that starts with an exclamation point (!lithiumSSO:). This is to prevent the app from trying to process the same cookie it's already processed more than 1 time, which we don't allow (for security reasons). We also put time limits on how long an SSO token is good for, so it's best practice to only set an SSO cookie right befor sending a browser to the community.
It shouldn't matter how you generate the cookie (server-side or ajax call), as long as the request is secure and cannot be used to get an sso token that lets you log in as another user.
If you are making an ajax call to another domain to get an sso cookie, make sure you have CORS configured correctly for that community and are sending the correct headers.
If an sso cookie is set by an ajax call, you should always reload the page (or make another ajax request with the sso cookie) since the sso processing happens on the server-side.
I googled "ajax can't set cookie firefox" and found this stackoverflow article:
Jquery Ajax Firefox not sending cookie (Chrome works)
Maybe what you're trying is related?
-Doug
Sign in to react to this post
"1" was searched 1,755 + 501 times one day in August?
What on earth could this be? Our community is closed to open registrations, and SSO authentication only.235Views
Sign in to react to this post3Comments