FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login
    1. Home
    2. Categories
    3. Q&A
    Log in to post
    Load new posts
    • Recently Replied
    • Recently Created
    • Most Posts
    • Most Votes
    • Most Views
    • R

      Manually verifying a JWT

      • • raghebmichael
      17
      0
      Votes
      17
      Posts
      14.3k
      Views

      G

      @raghebmichael said in Manually verifying a JWT:

      Something is very wrong. I don't know if this is something anybody else is facing, but I changed to a RS256 key and used the public key on jwt.io and it is still invalid. I cannot validate a JWT outside of /api/jwt/validate. This is a really big deal to me to be able to do something as simple as validating. Please let me know if I am in error, but if I can't get this to work I cannot continue using fusionauth and that's a big bummer to me as I had high hopes for this service.

      b63ceaca-e17c-48e4-b7cc-fe757eff696f-image.png

      This is exactly what I was looking for to solve my problem.
      Thank you very much.

    • G

      Unsolved Integrating FusionAuth as OTP Provider with Exchange Server using ADFS Authentication

      • • g.natsoulis
      2
      0
      Votes
      2
      Posts
      555
      Views

      danD

      @g-natsoulis

      Hiya, can you explain a little more about what you are looking for? I'm not quite sure what you mean by "an OTP provider for an Exchange server that has ADFS authentication set up?"

    • F

      Unsolved Maintenance Mode on Remote Server

      • • fusionauth 0
      2
      0
      Votes
      2
      Posts
      1.4k
      Views

      danD

      @fusionauth-0

      Hmmm. So you are saying that:

      you can connect from the ec2 instance to your postgresql instance. you can connect via the web to the fusionauth instance, but it is stuck in maintenance mode.

      Where is the postgresql instance running? Is it on the same ec2 instance as FusionAuth?

      What value are you putting for the hostname?

    • B

      Unsolved SQL error on request_frequencies Table

      • • becharam
      4
      0
      Votes
      4
      Posts
      1.6k
      Views

      danD

      @langnerfrancesco What version of FusionAuth are you using?

      What version of postgresql?

    • D

      Unsolved Cannot setup the first administrator account

      • • dadastakecrypto
      7
      1
      Votes
      7
      Posts
      2.2k
      Views

      danD

      @vvicazz That's great news!

    • B

      Unsolved How to invalidate jwt issued before deativating user?

      • • bharath.yadavally
      6
      0
      Votes
      6
      Posts
      5.3k
      Views

      danD

      @bharath-yadavally You could absolutely use the 2 step approach you outlined. There are two different approaches that have different strengths and weaknesses.

      The tradeoffs are that if you make those two calls, you're depending on the identity provider to be up and available to your backend service. You're tightly coupling the backend service to the identity provider.

      That can work fine, but as you scale, more and more backend services will be making those calls, and the idp and speedy connections to it become more and more critical to your application.

      Contrast that with the webhook approach, where the data is pushed to every backend service, and only when a user is deactivated. In this case, there'll be far less coupling with the identity provider, at the cost of more complexity on the backend service side.

      Hope that helps.

    • K

      Unsolved Using reconsile api to get access token for AzureAD OpenID Connect

      • • kushalborda1997
      2
      0
      Votes
      2
      Posts
      4.6k
      Views

      danD

      @kushalborda1997 Hiya,

      We recently updated the documentation to make it more clear you shouldn't use the /api/jwt/reconcile endpoint for any identity providers except the external JWT provider. We'll change the application to make the error message clearer; here's the tracking issue: https://github.com/FusionAuth/fusionauth-issues/issues/2074

      You should use the OIDC provider and the complete login endpoint. Here's documentation that should help: https://fusionauth.io/docs/v1/tech/apis/identity-providers/openid-connect#complete-an-openid-connect-login

      Hope that helps!

    • D

      Unsolved Registration email

      • • didier
      2
      0
      Votes
      2
      Posts
      699
      Views

      danD

      @didier I'm not sure I understand.

      You are saying you want to send the registration email yourself, not automatically with FusionAuth?

      (There are two possible verification emails. One is for a user creation, which verifies their email whenever someone creates a user, for any application. Another is for registration verification, which again checks their email but only when someone registers for a certain application.)

      If that is the case, use the skipVerification and skipRegistrationVerification settings if using the API. There are analogous settings in the admin UI as well.

      More documentation here: https://fusionauth.io/docs/v1/tech/apis/registrations#create-a-user-and-registration-combined

      and here: https://fusionauth.io/docs/v1/tech/core-concepts/applications#registration

      and here: https://fusionauth.io/docs/v1/tech/core-concepts/tenants#email

    • V

      Unsolved Refresh token revoked on logging in on multiple devices

      • • vindhyahegde2114
      6
      0
      Votes
      6
      Posts
      4.4k
      Views

      V

      @dan

      User logs in through authorization code grant flow

      Here goes the refresh token settings for the application:

      e34e22da-b37b-41e6-8816-88b43a8cbddd-image.png

      FusionAuth version being used is 1.36.6

      Thanks,
      Vindhya

    • A

      Unsolved Zero downtime

      • • alison.rafaelc
      2
      0
      Votes
      2
      Posts
      784
      Views

      danD

      @alison-rafaelc Hi Alison,

      It depends on how you architect the FusionAuth system, but in our FusionAuth cloud system, we see downtime of seconds to minutes for system upgrades (depending on the number of users and the data being migrated). We get this by swapping out one node at a time, running in an 3+ node cluster. Some details here: https://fusionauth.io/docs/v1/tech/installation-guide/cloud#upgrade-duration

      Worth noting that you control when you do the upgrade, unlike a typical multi-tenant saas.

      We have a number of customers and community members with thousands of tenants and millions of users so the numbers you mention seem fine. I'm glad you were able to stand up a FusionAuth cluster and load test it.

      Zero downtime upgrades are something we've discussed internally and have a strategy for, it just hasn't made it onto the roadmap yet.

      If you'd like to have a discussion with a technical sales team about FusionAuth and SLAs, I'm happy to have someone reach out to you.

    • I

      Unsolved Use FusionAuth for Server Auth

      • • imapotato
      2
      0
      Votes
      2
      Posts
      798
      Views

      danD

      @imapotato Heya,

      FusionAuth isn't really an AD/LDAP replacement. It doesn't support older protocols like RADIUS, Kerberos or even LDAP fully.

      When we are talking about machine to machine communication, we are referring to the client credentials OAuth grant. You can read more about that in the links below:

      https://fusionauth.io/docs/v1/tech/oauth/#example-client-credentials-grant

      https://fusionauth.io/docs/v1/tech/core-concepts/entity-management

    • Q

      Solved Identity provider logout

      logout • • quent
      4
      0
      Votes
      4
      Posts
      2.5k
      Views

      danD

      @quent I understand your position, and we appreciate the feedback.

      Can you please create a github issue linking to this forum post and with as much detail as you can provide (including, perhaps, sample logout urls provided by IdPs you are interested in)?

      https://github.com/fusionauth/fusionauth-issues/issues

    • K

      Unsolved This topic is deleted!

      • • kushalborda1997
      1
      0
      Votes
      1
      Posts
      3
      Views

      No one has replied

    • T

      Unsolved This topic is deleted!

      • • tassottiangelofederico463
      1
      0
      Votes
      1
      Posts
      21
      Views

      No one has replied

    • T

      Unsolved Is there any way to verify user as well as change its password with one API call?

      • • tsukhwani
      2
      0
      Votes
      2
      Posts
      2.9k
      Views

      danD

      @tsukhwani Not that I know of. I don't think you can verify a user's registration via API.

      You should be able to use the Update User API to update verify the user's email, though.

      From my reading of the docs, if you set skipVerification to true, it sets verified to true, and you can set the password at the same time.

    • F

      Unsolved In the dashboard, what are the blank applications?

      • • fred.fred
      2
      0
      Votes
      2
      Posts
      1.2k
      Views

      danD

      @fred-fred If no application id is provided when using the Login API, then there is no application in the reporting, since FusionAuth doesn't know the application. I'm not sure if you are using the Login API, but people can authenticate without an application id.

      Here's more documentation about this issue: https://fusionauth.io/docs/v1/tech/core-concepts/authentication-authorization

    • T

      Solved Duplicate port number in Google IdP redirect

      • • trevorr
      4
      0
      Votes
      4
      Posts
      1.3k
      Views

      H

      @trevorr said in Duplicate port number in Google IdP redirect:

      It appears I was running an old version locally (1.30.2). This issue has been fixed as of at least 1.41.2.

    • M

      Unsolved Connecting to fusionAuth as an OAuth2 in spring boot cloud gateway(webflux)

      • • mehdi.motrada
      2
      0
      Votes
      2
      Posts
      857
      Views

      danD

      @mehdi-motrada Have you worked through this tutorial: https://fusionauth.io/blog/2023/01/03/spring-and-fusionauth ?

    • V

      Identity Provider with no email?

      • • valentin.alt.raltchev99
      30
      0
      Votes
      30
      Posts
      76.1k
      Views

      T

      It looks like setting the email address in a lambda works for Facebook now (as of at least 1.41.2):

      if (!facebookUser.email) { user.email = facebookUser.id + '@no-email.facebook.com'; } 1/10/2023 10:10:33 PM Z Linking strategy [LinkByEmail] 1/10/2023 10:10:33 PM Z Resolved email to [] 1/10/2023 10:10:33 PM Z Resolved username to [null] 1/10/2023 10:10:33 PM Z Resolved unique Id to [115587478085870] 1/10/2023 10:10:33 PM Z Identity provider returned a unique Id [115587478085870]. 1/10/2023 10:10:33 PM Z A link has not yet been established for this external user. 1/10/2023 10:10:33 PM Z The user with the email address [] does not exist. 1/10/2023 10:10:33 PM Z Invoke configured lambda with Id [787cd34e-1618-4cd9-8156-936734cfe368] 1/10/2023 10:10:33 PM Z The lambda set or modified the initially resolved email. Email is now [115587478085870@no-email.facebook.com] 1/10/2023 10:10:33 PM Z Creating user: 1/10/2023 10:10:33 PM Z User is not registered for application with Id [e0da3f10-7efa-4a6b-95f8-fbf4894884b5] 1/10/2023 10:10:33 PM Z User has successfully been reconciled and logged into FusionAuth. 1/10/2023 10:10:33 PM Z Authentication type: FACEBOOK 1/10/2023 10:10:33 PM Z Authentication state: Authenticated
    • danD

      Are there any disallowed characters in passwords?

      passwords • • dan
      3
      0
      Votes
      3
      Posts
      1.8k
      Views

      robotdanR

      In the UI you can select "Special character" to require at least one special character. If anyone is looking to understand which characters will satisfy this requirement read on.

      If you view the tooltip or the API - you’ll see the configuration is actually for non-alpha-numeric.

      https://fusionauth.io/docs/v1/tech/apis/tenants#create-a-tenant

      tenant.passwordValidationRules.requireNonAlpha
      Whether to force the user to use at least one non-alphanumeric character.

      So instead of limiting this to a specific set of special characters, we allow it to be any character that is not a unicode alphabetic and not a digit. In this way, we do not artificially limit the entropy of the password by saying you must use one or more characters for a finite set of "special characters" as you may be used to seeing on some login forms.