The RelayState cookie is being set when performing an SP-initiated login in an app (example: CityWorks and My Esri) that uses the ArcGIS Enterprise portal to authenticate users when Okta is the IdP and causes an IdP-initiated login to another resource that uses the cookie (like the ArcGIS Enterprise portal or ArcGIS Online) to reroute to the resource where the SP-initiated login is generated.
上次发布: April 24, 2020ArcGIS Online
漏洞 ID 编号
BUG-000129499
已提交
March 19, 2020
上次修改时间
March 21, 2025
适用范围
ArcGIS Online
找到的版本
7.4
操作系统
Windows OS
操作系统版本
2016 64 Bit
状态
Will Not Be Addressed
开发团队已考虑过该问题或请求,并决定不会解决该问题。 问题的“其他信息”部分可能包含进一步说明。
附加信息
The development team has considered the issue or request and concluded it will not be addressed. If this is still a concern, contact Esri Support Services.
解决办法
Add the EditThisCookie chrome extension.
Block the RelayState cookie by adding a rule for the following information using the extension:
Domain: organizationName.maps.arcgis.com
Name: RelayState
Value: any
Clear cache and perform workflow again to be routed to ArcGIS Online instead of My Esri.