[keycloak-user] XHRs resulting in 401 unauthorized

Gianluca Diodato gdiodato at ifc.cnr.it
Mon Jul 29 09:41:03 EDT 2019


Hi All, 
We have a problem in our platform configuration: 

Server 1: 
Apache 2.4.x 
mod_auth_openidc 2.3.11 
Symfony 3.x application + Javascript & Ajax code (no headers into our xhr requests) 

Server 2: 
Keycloack 4.8.3 Final (client is confidential type) 

All work fine but after few minutes (about 4 minutes) any requests (XHRs)fails with error 401 unauthorized into browser. 
To bypass the error, we added this parameter into ssl.conf (attached file): 

OIDCSessionInactivityTimeout 1800 

But we would find a definitive solution. 
We googled about this problem: 

https://github.com/zmartzone/mod_auth_openidc/wiki/Cookies 
https://github.com/zmartzone/mod_auth_openidc/wiki/Access-Tokens-and-Refresh-Tokens 

but we not found anything help us. We missed something? 

Comments and suggestions are welcome. 

Bests 
Gianluca Diodato
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ssl.conf
Type: application/octet-stream
Size: 10151 bytes
Desc: not available
Url : http://lists.jboss.org/pipermail/keycloak-user/attachments/20190729/47f5c18d/attachment-0001.obj 


More information about the keycloak-user mailing list