Work Item email links not working when SAML SSO enabled and fresh login

Which IIQ version are you inquiring about?

8.4

Please share any images or screenshots, if relevant.

N/A

Please share any other relevant files that may be required (for example, logs).

N/A

Share all details about your problem, including any error messages you may have received.

We have SAML SSO enabled and we also provide direct links to workitems in email templates to owners of the workitems. When users click on these links and they haven’t logged in the SSO Login page is shown and afterwards the URL that users are taken to doesn’t have everything after the # icon

e.g. https://10.4.16.224:8443/workitem/commonWorkItem.jsf#/commonWorkItem/0a0410e09875103681987b185fef2a48
Gets converted to / sent to
https://10.4.16.224:8443/workitem/commonWorkItem.jsf

Has anyone else seen this? and if so how did you resolve it ?

To be clear, if the user already has a session the link works fine - i.e. user is taken directly to the work item

not sure what is you email template has , but can you add below in your email template and test

<a href="$spTools.formatURL('workitem/workItem.jsf?id=')$item.id">

Email template has this
<p>Click the following link to access the Workitem in IdentityIQ directly: <a href="${baseUrl}workitem/commonWorkItem.jsf#/commonWorkItem/${workItem.id}"> $!{item.description}</a>.</p>

not sure workItem.jsf exists in the new version of IIQ

It’s completely depend on you IDP (identity provider), what url they are using after authentication to redirect user. You might need to check with your IDP (SSO application aka IDP provider) team.

Which IDP you are using for the authentication?

You can give a try to redirect URL in your email template.

http://10.4.16.224:8443/ui/rest/redirect?rp1=/workitem/commonWorkItem.jsf&rp2=commonWorkItem/0a0410e09875103681987b185fef2a48

Thank you for the suggestion, I haven’t had time to test it yet.
I’ve been able to reproduce this with 2 different IDPs so I’m not sure its dependent on the IDP.
I will let you know how the suggested change to the URL in the email goes

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.