jenkinsci / jenkinsci/openmfa-plugin

Initial MFA verification POST after login does not include Jenkins crumb

Open
#12 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
3
Forks
2
PR merge metrics
No merged PRs in 30d

Description

### Jenkins and plugins versions report

Environment

Jenkins: 2.568.2
OpenMFA: 111.v347db_32e7f24
Browser: Firefox
Reverse proxy: HAProxy with correct X-Forwarded-* headers


```text
Jenkins: 2.568.2
OS: Linux - 6.1.0-42-cloud-amd64
Java: 21.0.9 - Eclipse Adoptium (OpenJDK 64-Bit Server VM)
---
ansicolor:536.v13fa_b_860c267
ant:520.vd082ecfb_16a_9
antisamy-markup-formatter:173.v680e3a_b_69ff3
apache-httpcomponents-client-4-api:4.5.14-269.vfa_2321039a_83
asm-api:9.10.1-216.va_9256d3b_844b_
avatar:28.v2e722a_1e67ea_
aws-credentials:254.v978a_5e206a_d7
aws-java-sdk-ec2:1.12.780-480.v4a_0819121a_9e
aws-java-sdk-minimal:1.12.780-480.v4a_0819121a_9e
aws-java-sdk2-core:2.42.33-70.vd69c0763fa_60
aws-java-sdk2-ec2:2.42.33-70.vd69c0763fa_60
bootstrap5-api:5.3.8-895.v4d0d8e47fea_d
bouncycastle-api:2.30.1.84-291.v9f17b_21896e2
branch-api:2.1280.v0d4e5b_b_460ef
build-timeout:1.40
build-user-vars-plugin:214.va_eed2ed849ca_
caffeine-api:3.2.3-194.v31a_b_f7a_b_5a_81
catppuccin-theme:15.v3940ff14e600
checks-api:402.vca_263b_f200e3
cloudbees-folder:6.1100.ve9eed61d16c4
commons-lang3-api:3.20.0-109.ve43756e2d2b_4
commons-text-api:1.15.0-218.va_61573470393
credentials:1502.v5c95e620ddfe
credentials-binding:725.ve52b_2328a_fde
customizable-header:295.v2544b_ca_19b_97
dark-theme:652.vea_da_dfea_e769
display-url-api:2.217.va_6b_de84cc74b_
durable-task:671.v340ff7959010
echarts-api:6.0.0-1247.vf3e35a_c1813f
eddsa-api:0.3.0.1-29.v67e9a_1c969b_b_
email-ext:1933.1935.v276319e3cc47
flatpickr-api:4.6.13-32.v60a_51029c136
font-awesome-api:7.2.0-965.ve3840b_696418
git:5.10.1
git-client:6.6.1
git-server:137.ve0060b_432302
github:1.46.0.1
github-api:1.330-492.v3941a_032db_2a_
github-branch-source:1967.1970.vd86979736546
gradle:2.19.1244.v1f9866817fec
gson-api:2.14.0-201.v8eefe5515533
instance-identity:203.v15e81a_1b_7a_38
ionicons-api:94.vcc3065403257
jackson-annotations2-api:2.22-19.v10a_a_582ea_26e
jackson2-api:2.21.2-436.v29efdb_7418ff
jackson3-api:3.1.4-81.v804303fd947a_
jakarta-activation-api:2.1.4-1
jakarta-mail-api:2.1.5-1
jakarta-xml-bind-api:4.0.9-19.v2b_a_5b_44d9a_1c
javax-activation-api:1.2.0-8
jaxb:2.3.9-143.v5979df3304e6
jjwt-api:0.13.0-141.vd58b_a_9592b_6c
joda-time-api:2.14.2-193.v422b_efce56e0
jquery3-api:3.7.1-619.vdb_10e002501a_
json-api:20260522-217.v0b_18b_8cd4672
json-path-api:3.0.0-218.vcd4dd1355de2
jsoup:1.22.2-95.vc5d00f1eb_42d
junit:1403.vd9d1413fd205
ldap:807.809.vd3a_4e5e4ec98
mailer:534.v1b_36f5864073
matrix-auth:3.2.10
matrix-project:870.v9db_fcfc2f45b_
metrics:4.2.37-494.v06f9a_939d33a_
mina-sshd-api-common:2.17.1-187.v0341274c2905
mina-sshd-api-core:2.17.1-187.v0341274c2905
okhttp-api:5.3.2-200.vedb_720a_cf1f8
openmfa:111.v347db_32e7f24
pipeline-build-step:584.vdb_a_2cc3a_d07a_
pipeline-github-lib:65.v203688e7727e
pipeline-graph-view:918.vf572523124f2
pipeline-groovy-lib:798.v5cc688825312
pipeline-input-step:551.vdff487c5998c
pipeline-milestone-step:152.v6e22b_8cfc66c
pipeline-model-api:2.2289.v6f731d0a_02da_
pipeline-model-definition:2.2289.v6f731d0a_02da_
pipeline-model-extensions:2.2289.v6f731d0a_02da_
pipeline-stage-step:345.va_96187909426
pipeline-stage-tags-metadata:2.2289.v6f731d0a_02da_
plain-credentials:199.v9f8e1f741799
plugin-util-api:6.1192.v30fe6e2837ff
powershell:185.v7a_026da_c54ee
prism-api:1.30.0-717.vb_f8360844b_53
purge-job-history:74.vf21030329dda_
resource-disposer:0.25
role-strategy:867.vd09254229f9b_
saferestart:102.v4dc1b_9636a_ee
scm-api:728.vc30dcf7a_0df5
script-security:1402.1405.vc96e74964250
scriptler:456.v52a_410f4cdb_8
snakeyaml-api:2.5-149.v72471e9c6371
snakeyaml-engine-api:3.0.1-5.vd98ea_ff3b_92e
ssh-credentials:372.va_250881b_08cd
ssh-slaves:3.1097.v868116049892
sshd:3.384.vc89b_5e138cf9
structs:362.va_b_695ef4fdf9
theme-manager:346.v06cca_64c6a_37
timestamper:1.30
token-macro:477.vd4f0dc3cb_cf1
trilead-api:2.284.v1974ea_324382
variant:70.va_d9f17f859e0
woodstox-core-api:7.1.1-1.v4d297985f397
workflow-aggregator:608.v67378e9d3db_1
workflow-api:1413.v2ff1a_5e720fa_
workflow-basic-steps:1098.v808b_fd7f8cf4
workflow-cps:4360.v2020e8819a_d6
workflow-durable-task-step:1479.v56e587f413a_7
workflow-job:1571.1580.v18e46842c125
workflow-multibranch:821.vc3b_4ea_780798
workflow-scm-step:466.va_d69e602552b_
workflow-step-api:724.v538c2362b_dfb_
workflow-support:1015.v785e5a_b_b_8b_22
ws-cleanup:0.49

```

### What Operating System are you using (both controller, and any agents involved in the problem)?

Debian Trixy on host, running Docker and Jenkins as container

### Reproduction steps

Navigate to Jenkins https://jenkins.domain.com
Enter your credentials
Supply MFA code (autofilled by 1Password)
Get the 403 page
Browse to https://jenkins.domain.com again
MFA 6 digit form appears but no autofill
Enter 6 digit code
Logged into Jenkins

### Expected Results

After entering the MFA code to be in Jenkins as user

The first POST to `/mfa-login/verify` should include Jenkins-Crumb.

I could not find any crumb info in developer tools -> Network -> Request

When I re-navigate to the Jenkins url, I do see on `/mfa-login/verify` (status 302) crumb information

From the 403 page in developer tools -> network -> request :
```
from="/"
x-plugin-openmfa-totp="redacted"
```

From the 302 page in developer tools -> network -> request :
```
from="/"
x-plugin-openmfa-totp="redacted"
Jenkins-Crumb="redacted"
json '{"from":"/","":["1","2","3","4","5","6"],"x-plugin-openmfa-totp":"123456","Jenkins-Crumb":"redacted"}'
```
Note that I redacted values and changed the totp value to "123456"

### Actual Results

from=/
x-plugin-openmfa-totp=redacted

### Anything else?

It sometimes works as expected, about 2 out of 10 times I would say but I did not measure it exactly
The work around atm is to tell users to try again and then it works but this is not a permanent message we want to give. I've tried my best to make sure HAProxy is configured properly and other then using this as backend, I have no idea what else to set in there:
```
In default setting I have:
option forwardfor
which would lead to this basically:
X-Forwarded-For:

Backend config in HAProxy:
backend app-jenkins
http-request set-header X-Forwarded-Proto https
http-request set-header X-Forwarded-Port 443
http-request set-header X-Forwarded-Host %[req.hdr(Host)]
server jenkins 127.0.0.1:4100 check maxconn 20
```

### Are you interested in contributing a fix?

_No response_

Contributor guide

Open the contributing guide

Research direction

Reproduce the login flow and inspect the first POST to `/mfa-login/verify` in the browser network tools, comparing it with the successful retry. The fix is done when the initial MFA verification request includes Jenkins-Crumb and logs the user in without requiring a second attempt.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authentication, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.