Hi guys, I'm deploying Datahub on dev environment...
# all-things-deployment
c
Hi guys, I'm deploying Datahub on dev environment using Helm. I just wonder is there any configuration that I can use to set the timeout for Datahub session/cookies? To be more detailed, I want user to be signed out automatically after 1 hour of logging in. Thanks in advance. I'm using Datahub with Helm chart verion 0.2.179. In addition, I'm using Keycloak to allow user to sign in Datahub. I set token timeout from Keycloak in 1 hour, but it's just the session from Keycloak. Clients still have to sign out manually from Datahub for the session from Keycloak to be applied.
plus1 1
a
@orange-night-91387 Could you help here? Thanks!
o
cc: @dazzling-yak-93039
a
Hey, we do have such a configuration!
Copy code
# Login session expiration time
auth.session.ttlInHours = 720
auth.session.ttlInHours = ${?AUTH_SESSION_TTL_HOURS}
These go in
application.conf
which is part of the frontend deployment.
d
There is also a helm chart value for it as well outside of just using extraEnvs, if you're using helm
c
Thank u so much. I'll try it. Btw is there any configuration that can help to end session at some predefined time (e.g. at 18.00) every day)
a
I don't know about that, sorry
c
Hi guys, after trying the solution proposed above, I just noticed a problem that is after 1 hour of session time, when I trying to access Datahub, I got error 502 like in this picture. (The Cookies PLAY_SESSION, bid and Local Storage seems not to be cleared and if I clear the cookies PLAY_SESSION then I can access the login page again to authenticate my account). Can you take a look at my value file and see if there were any misconfiguration & propose any possible solutions so that whenever I click sign out or the session comes to an end, if I access Datahub, there will be no error like this again and redirect me to my login page? Thanks in advance.
Hello @dazzling-yak-93039. Could you please help with the problem above? Thanks.
d
Tagging this week's OSS oncall @brainy-tent-14503
b
Can you share the frontend logs? If your ingress is returning 502, then likely there is a 500 in the frontend logs. The frontend should respond with a 4xx error and a header to delete the expired session cookie instead.
c
After checking file datahub-frontend.debug.log in /tmp/datahub/logs/datahub-frontend of front-end port, I get this log:
2023-09-06 15:20:51,400 [application-akka.actor.default-dispatcher-12] DEBUG o.p.o.r.OidcRedirectionActionBuilder - Authentication request url: <https://keycloak.test.com.vn/auth/realms/datahub/protocol/openid-connect/auth?scope=openid+profile+email&response_type=code&redirect_uri=https%3A%2F%2Fdatahub-fe.test.com.vn%2Fcallback%2Foidc&state=1a57250182&code_challenge_method=S256&client_id=datahub&code_challenge=8aKblhBAKlj-U9uV0WV3u_s4OtnBp5mxf6EREldnH8A>
2023-09-06 15:20:51,401 [application-akka.actor.default-dispatcher-12] DEBUG o.p.play.http.PlayHttpActionAdapter - requires HTTP action: 302
2023-09-06 15:20:51,404 [application-akka.actor.default-dispatcher-13] DEBUG o.p.o.r.OidcRedirectionActionBuilder - Authentication request url: <https://keycloak.test.com.vn/auth/realms/datahub/protocol/openid-connect/auth?scope=openid+profile+email&response_type=code&redirect_uri=https%3A%2F%2Fdatahub-fe.test.com.vn%2Fcallback%2Foidc&state=bf2bbac13e&code_challenge_method=S256&client_id=datahub&code_challenge=PoZZecW91cNv6lpEa47fB_ZenaMKmBeER9wg--QNWgw>
2023-09-06 15:20:51,404 [application-akka.actor.default-dispatcher-13] DEBUG o.p.play.http.PlayHttpActionAdapter - requires HTTP action: 302
a
Looks like maybe it's getting caught in a redirect loop and timing out? Is this the whole log?
b
+1 it would be useful to get a more complete log, do these messages repeat?
c
That's all the log that I found
There are previous logs but it's of the previous successful session. The log shown at 15:20 is when the session is over (both in datahub and in keycloak)
Accessing the URL in log is the SignIn UI of Keycloak. It seems that the session in Keycloak is over and it can't authenticate users? But still don't know why it doesn't clear the PLAY_SESSION cookie and redirect user to Keycloak for authentication.
a
We’re still investigating this, we’ll see if we can write a test case with a mock idp and debug from there. At least asserting and correcting the PLAY_SESSION cookie as well as looking at the redirect.
c
Hello, is there any updates on this?
a
Unfortunately I haven’t had bandwidth this week to debug this issue further. @orange-night-91387 is taking a look at the PLAY_SESSION cookie and will likely have an update sometime next week.
Based on what I'm seeing, once it reaches the point that outputs the log you see above it's hitting the redirect url you've provided. At that point any errors with actually hitting that URL should be getting caught and logged, but the logs don't show any. Does keycloak output any logs that you could see what's happening when it hits the redirect url?
c
unfortunately, I'm not operating the keycloak system so I cannot check the error log from keycloak
t
We're having the exact same issues with our SSO setup although we don't use Keycloak. Sporadically, we're getting 502 errors and after clearing the cache or when using incognito mode, the login works fine. I assume it's because of an expired PLAY_SESSION. Unfortunately, there are no related logs in the frontend or GMS pods that would help. Was there any update on this @brainy-tent-14503? We're still using Datahub 0.10.4. What we also see, which might be related, is that with SSO enabled, a user is not able to log out. There's no error the user just stays logged in.
a
There is a pending fix for expiration merged for the next release. I can’t guarantee this is the fix for this issue, however it does get the browser to remove the cookie for long running sessions.
👍 1
t
Great, thanks for the update. We'll try it out as soon as it gets released.