FAS login occasionally fails with HTTP 400. #13280

Closed
opened 2026-04-20 17:14:23 +00:00 by rokejulianlockhart · 20 comments

Description of request

At id.fedoraproject.org/openidc/Continue?ipsilon_transaction_id=88cb46e1-8b98-4f74-82b9-82135336eccb, as I frequently do, I observed the undermentioned, upon attempted, unsuccessful login:

400 – Bad Request

Invalid Transaction ID

If the error persists and if you think this is an error, contact Fedora Infra to resolve the problem.

I've yet to acquire HAR, because it rarely occurs consequtively, despite frequently recurring. Regardless, this has been previously reported elsewhere, many times:

However, no tickets, since the transferral from Pagure, remain open, to track this.

My Environment

  1. #!/usr/bin/env sh
    rpm -qf $(command -v firefox-nightly) \
    	--queryformat "$(
    		cat <<'EOF'
    Name: %{NAME}
    Version: %{VERSION}
    Release: %{RELEASE}
    Architecture: %{ARCH}
    Install Date: %{INSTALLTIME:date}
    Size: %{SIZE}
    Signature: %{SIGPGP:pgpsig}
    Source RPM: %{SOURCERPM}
    Build Date: %{BUILDTIME:date}
    Build Host: %{BUILDHOST}
    Packager: %{PACKAGER}
    Vendor: %{VENDOR}
    EOF
    	)"$'\n' | yq -P
    

  2. Name: firefox-nightly
    Version: 151.0a1
    Release: 20260420091406
    Architecture: x86_64
    Install Date: Mon 20 Apr 2026 17:57:44 BST
    Size: 384505308
    Signature: (none)
    Source RPM: firefox-nightly-151.0a1-20260420091406.src.rpm
    Build Date: Mon 20 Apr 2026 12:24:33 BST
    Build Host: b3a886767332
    Packager: (none)
    Vendor: Mozilla
    
### Description of request At [`id.fedoraproject.org/openidc/Continue?ipsilon_transaction_id=88cb46e1-8b98-4f74-82b9-82135336eccb`](https://id.fedoraproject.org/openidc/Continue?ipsilon_transaction_id=88cb46e1-8b98-4f74-82b9-82135336eccb), as I frequently do, I observed the undermentioned, upon attempted, unsuccessful login: > # 400 – Bad Request > > Invalid Transaction ID > > If the error persists and if you think this is an error, contact <a href="https://forge.fedoraproject.org/infra/tickets/issues">Fedora Infra</a> to resolve the problem. I've yet to acquire HAR, because it rarely occurs consequtively, despite frequently recurring. Regardless, this has been previously reported elsewhere, many times: - [`issues/12294`](https://forge.fedoraproject.org/infra/tickets/issues/12294#issuecomment-392665) - [`issues/12715`](https://forge.fedoraproject.org/infra/tickets/issues/12715#issuecomment-392663) - [`issues/12534`](https://forge.fedoraproject.org/infra/tickets/issues/12534#issuecomment-268161) However, no tickets, since the transferral from Pagure, remain open, to track this. #### My Environment 1. <p></p><details><p></p> ~~~sh #!/usr/bin/env sh rpm -qf $(command -v firefox-nightly) \ --queryformat "$( cat <<'EOF' Name: %{NAME} Version: %{VERSION} Release: %{RELEASE} Architecture: %{ARCH} Install Date: %{INSTALLTIME:date} Size: %{SIZE} Signature: %{SIGPGP:pgpsig} Source RPM: %{SOURCERPM} Build Date: %{BUILDTIME:date} Build Host: %{BUILDHOST} Packager: %{PACKAGER} Vendor: %{VENDOR} EOF )"$'\n' | yq -P ~~~ <p></p></details><p></p> 1. <blockquote> ~~~YAML Name: firefox-nightly Version: 151.0a1 Release: 20260420091406 Architecture: x86_64 Install Date: Mon 20 Apr 2026 17:57:44 BST Size: 384505308 Signature: (none) Source RPM: firefox-nightly-151.0a1-20260420091406.src.rpm Build Date: Mon 20 Apr 2026 12:24:33 BST Build Host: b3a886767332 Packager: (none) Vendor: Mozilla ~~~ </blockquote>
rokejulianlockhart added spent time 2026-04-20 17:14:45 +00:00
20 minutes
Member

We see this occasionally, where it fixes itself if you go back and try again ... and it maybe happens more often if you leave the window open before doing the FAS authentication.

Nobody really knows why, and we're hoping that it'll get fixed as part of the migration to keycloak (hopefully soon, post freeze, now). I can leave this issue open for a bit.

We see this occasionally, where it fixes itself if you go back and try again ... and it maybe happens more often if you leave the window open before doing the FAS authentication. Nobody really knows why, and we're hoping that it'll get fixed as part of the migration to keycloak (hopefully soon, post freeze, now). I can leave this issue open for a bit.

@james, thanks. I shall link this to issues/13188, then.

@james, thanks. I shall link this to [`issues/13188`](https://forge.fedoraproject.org/infra/tickets/issues/13188#issue-99945), then.
In retrospect, the undermentioned is irrelevant: <p></p><details><p></p> Strangely, I've had the error page also cause: 1. [`crash-stats.mozilla.org/report/index/76e72c01-153f-4ba2-a629-8cb910260515`](https://crash-stats.mozilla.org/report/index/76e72c01-153f-4ba2-a629-8cb910260515) 1. [`crash-stats.mozilla.org/report/index/4ed413c3-6df3-4978-9979-96ceb0260515`](https://crash-stats.mozilla.org/report/index/4ed413c3-6df3-4978-9979-96ceb0260515) 1. [`crash-stats.mozilla.org/report/index/73f72c59-1d4c-4c23-9ea3-d631b0260515`](https://crash-stats.mozilla.org/report/index/73f72c59-1d4c-4c23-9ea3-d631b0260515) …if at all relevant! <video src="/attachments/dafed6de-85e9-4e06-8b00-c073d6c92653" title="@{&#39;Date&#39;=&#39;20260515T011038+0100&#39;; &#39;Type&#39;=&#39;Video&#39;; &#39;Origin&#39;=&#39;" controls></video> <p></p></details><p></p>

This recently occurred, at id.fedoraproject.org/saml2/SSO/Continue?ipsilon_transaction_id=b766d92d-002c-4da0-9526-fddf8881fc38:

<!doctype html>
<html>

    <head>
        <meta charset="UTF-8">
        <title>Bad Request</title>
        <link href="https://apps.fedoraproject.org/global/fedora-bootstrap-1.5.0/fedora-bootstrap.min.css" rel="stylesheet">
        <link href='/ui/res/login.css' rel='stylesheet' type='text/css'>
        <meta name="generator" content="Ipsilon">
    </head>

    <body>
        <div class="navbar navbar-light masthead">
            <div class="container justify-content-between"><img alt="logo" src="/ui/res/FedoraAccounts.png" height=40px />
                <div></div>
            </div>
        </div>
        <div class="bodycontent py-5 min-height-50">
            <div class="container">
                <h1 class="text-center"><strong>400 - Bad Request</strong></h1>
                <p class="text-center">Invalid transaction id</p>
                <p class="text-center">If the error persists and if you think this is an error, contact <a href="https://forge.fedoraproject.org/infra/tickets/issues">Fedora Infra</a> to resolve the problem.</p>
            </div>
        </div>

…when attempting to authenticate at pagure.io/login/?next=https://pagure.io/ipsilon/issue/398.

bugzilla.mozilla.org/show_bug.cgi?id=2051153#c3 and bugzilla.mozilla.org/show_bug.cgi?id=2051153#c3 made this difficult to diagnose:

Screenshot_20260630_142620

However, because I couldn't get the entire flow to reproduce the failure (although ipsilon_transaction_id=870287d6-9603-4741-805b-35f51abda1d8 occurred soon afterward), even the -jsconsole didn't assist — I solely observe a request for the FAS logo:

Screenshot_20260630_142800

My Environment

The Output Of about:support, at ./attachments/ 1 2

This recently occurred, at [`id.fedoraproject.org/saml2/SSO/Continue?ipsilon_transaction_id=b766d92d-002c-4da0-9526-fddf8881fc38`](https://id.fedoraproject.org/saml2/SSO/Continue?ipsilon_transaction_id=b766d92d-002c-4da0-9526-fddf8881fc38#:~:text=400%20%2D%20Bad%20Request,Infra%20to%20resolve%20the%20problem%2E): <blockquote> ~~~HTML <!doctype html> <html> <head> <meta charset="UTF-8"> <title>Bad Request</title> <link href="https://apps.fedoraproject.org/global/fedora-bootstrap-1.5.0/fedora-bootstrap.min.css" rel="stylesheet"> <link href='/ui/res/login.css' rel='stylesheet' type='text/css'> <meta name="generator" content="Ipsilon"> </head> <body> <div class="navbar navbar-light masthead"> <div class="container justify-content-between"><img alt="logo" src="/ui/res/FedoraAccounts.png" height=40px /> <div></div> </div> </div> <div class="bodycontent py-5 min-height-50"> <div class="container"> <h1 class="text-center"><strong>400 - Bad Request</strong></h1> <p class="text-center">Invalid transaction id</p> <p class="text-center">If the error persists and if you think this is an error, contact <a href="https://forge.fedoraproject.org/infra/tickets/issues">Fedora Infra</a> to resolve the problem.</p> </div> </div> ~~~ </blockquote> …when attempting to authenticate at [`pagure.io/login/?next=https://pagure.io/ipsilon/issue/398`](https://pagure.io/login/?next=https://pagure.io/ipsilon/issue/398). [`bugzilla.mozilla.org/show_bug.cgi?id=2051153#c3`](https://bugzilla.mozilla.org/show_bug.cgi?id=2051153#c3) and [`bugzilla.mozilla.org/show_bug.cgi?id=2051153#c3`](https://bugzilla.mozilla.org/show_bug.cgi?id=2043908#c0) made this difficult to diagnose: ![`Screenshot_20260630_142620`](/attachments/7b48f944-5244-4d0b-b24c-253bfdbd5a13) However, because I couldn't get the entire flow to reproduce the failure (although [`ipsilon_transaction_id=870287d6-9603-4741-805b-35f51abda1d8`](https://id.fedoraproject.org/openidc/Continue?ipsilon_transaction_id=870287d6-9603-4741-805b-35f51abda1d8) occurred soon afterward), even the `-jsconsole` didn't assist — I solely observe a request for the FAS logo: ![`Screenshot_20260630_142800`](/attachments/ad453175-1521-4ca1-b2e0-187ace10d8da) #### My Environment [The Output Of `about:support`, at `./attachments/`](/attachments/6cda71fc-0dcd-498b-b157-b3edff266bb6) [^1] [^2] [^1]: [`codeberg.org/forgejo/forgejo/issues/13259`](https://codeberg.org/forgejo/forgejo/issues/13259#issue-6033575) [^2]: [`codeberg.org/forgejo/forgejo/issues/13260`](https://codeberg.org/forgejo/forgejo/issues/13260#issue-6033620)

I hit the same error just now. It's a very common problem, at least for me.

I hit the same error just now. It's a very common problem, at least for me.
Owner

I think we figured out what this problem was and have worked around it.

If any of you still see it, please let us know.

I think we figured out what this problem was and have worked around it. If any of you still see it, please let us know.

@kevin, unfortunately, this continues to consistently reproduce on every first login:

Screenshot_20260731_171237

@kevin, unfortunately, this continues to consistently reproduce on every first login: ![`Screenshot_20260731_171237`](/attachments/cd2be84b-7095-46bf-87b4-36234071a71e)

It happened to me ~1 hour ago too

It happened to me ~1 hour ago too
Owner

sigh. I had to reboot one of the backends and you may have testing right when it rebooted.

Can you try again now?

sigh. I had to reboot one of the backends and you may have testing _right_ when it rebooted. Can you try again now?
Owner

ok, next question: Do you have 'advanced tracking protection' enabled? If you disable it does the problem go away?

ok, next question: Do you have 'advanced tracking protection' enabled? If you disable it does the problem go away?

@kevin, about:config returns:

privacy.trackingprotection.enabled: false
privacy.trackingprotection.socialtracking.enabled: false
privacy.trackingprotection.pbmode.enabled: false
privacy.trackingprotection.fingerprinting.enabled: false
privacy.trackingprotection.allow_list.hasUserInteractedWithETPSettings: true

…whereas about:preferences#etpCustomize:~:text=Customize%20tracking%20protection returns:

image

Additionally, I attempted to acquire HAR again, but it ceased to reproduce, again! 1

@kevin, `about:config` returns: ~~~YAML privacy.trackingprotection.enabled: false privacy.trackingprotection.socialtracking.enabled: false privacy.trackingprotection.pbmode.enabled: false privacy.trackingprotection.fingerprinting.enabled: false privacy.trackingprotection.allow_list.hasUserInteractedWithETPSettings: true ~~~ …whereas `about:preferences#etpCustomize:~:text=Customize%20tracking%20protection` returns: ![image](/attachments/7eb2e2b0-1a70-46a7-b03a-45dba907d602) Additionally, I attempted to acquire HAR again, but it ceased to reproduce, again! [^1] [^1]: [`/attachments/0203651b-5fd4-4afe-9179-4531ebc69105`](/attachments/0203651b-5fd4-4afe-9179-4531ebc69105)

I use the defaults that come with my https://zen-browser.app/ but I have many, many trackingprotection related settings in my about:config. I'll try to disable them and see.

I use the defaults that come with my https://zen-browser.app/ but I have many, many `trackingprotection` related settings in my `about:config`. I'll try to disable them and see.

Was getting that "400 – Bad Request" when trying to FAS login in on https://bodhi.fedoraproject.org/updates/FEDORA-2026-2551d0d66b and https://src.fedoraproject.org/rpms/python-ase

Tried from both Google Chrome (Version 150.0.7871.186 (Official Build) (64-bit)) and Firefox (153.0.1), also in private windows.

Made 5 failed attempts, then cleaned all https://src.fedoraproject.org cookies, and succeeded to login onto it after two more failed attempts in Google chrome.

image

Was getting that "400 – Bad Request" when trying to FAS login in on https://bodhi.fedoraproject.org/updates/FEDORA-2026-2551d0d66b and https://src.fedoraproject.org/rpms/python-ase Tried from both Google Chrome (Version 150.0.7871.186 (Official Build) (64-bit)) and Firefox (153.0.1), also in private windows. Made 5 failed attempts, then cleaned all https://src.fedoraproject.org cookies, and succeeded to login onto it after two more failed attempts in Google chrome. ![image](/attachments/a8e80f04-96c4-4a31-aaf9-69a8ef521f84)
125 KiB
Member

Hey folks. I have spent a few hours on this, I think I may know where it's coming from. I think it's a bug in Ipsilon.

Ipsilon defines pages as objects, which are exposed by CherryPy. However, in ipsilon.login.common.LoginFormBase, it stores the current transaction as an instance variable in self.trans. I think this object gets overwritten if another login happens in parallel, because this does not look thread-safe. As a result the transaction id does not match the cookie anymore and is considered invalid.

I'll keep looking at this tomorrow and attempt to fix it, but I wanted to write this down here so others know we're working on it (and I don't forget everything on Monday ;-) )

Hey folks. I have spent a few hours on this, I think I may know where it's coming from. I think it's a bug in Ipsilon. Ipsilon defines pages as objects, which are exposed by CherryPy. However, in `ipsilon.login.common.LoginFormBase`, it stores the current transaction as an instance variable in `self.trans`. I think this object gets overwritten if another login happens in parallel, because this does not look thread-safe. As a result the transaction id does not match the cookie anymore and is considered invalid. I'll keep looking at this tomorrow and attempt to fix it, but I wanted to write this down here so others know we're working on it (and I don't forget everything on Monday ;-) )
Member

I've set mod_wgi to 1 thread only (and added 2 processes to compensate). Let's see if it helps.

I've set `mod_wgi` to 1 thread only (and added 2 processes to compensate). Let's see if it helps.
Owner

Oops. I ran playbooks and I think it overrode your changes. ;( Sorry about that...

Oops. I ran playbooks and I think it overrode your changes. ;( Sorry about that...
Member

No worries, I've put it back.
I'll commit it to ansible too because we should probably observe this for a few days / week(s).

No worries, I've put it back. I'll commit it to ansible too because we should probably observe this for a few days / week(s).
Member

OK I think that fixed the issue. Of course the proper fix would be to have Ipsilon use thread-local variables instead of class attributes, using for example cherrypy.thread_data, but that would be a much larger change that would impact multiple places in Ipsilon and should be properly tested. For now, I think using processes instead of threads is sufficient, as we plan to replace Ipsilon soonish.

OK I *think* that fixed the issue. Of course the proper fix would be to have Ipsilon use thread-local variables instead of class attributes, using for example `cherrypy.thread_data`, but that would be a much larger change that would impact multiple places in Ipsilon and should be properly tested. For now, I think using processes instead of threads is sufficient, as we plan to replace Ipsilon soonish.
Member

If the problem happens again, please reopen this ticket.

If the problem happens again, please reopen this ticket.

the proper fix would be to have Ipsilon use thread-local variables

@abompard, has a ticket been submitted for that?

> the proper fix would be to have Ipsilon use thread-local variables @abompard, has a ticket been submitted for that?
Sign in to join this conversation.
No milestone
No project
No assignees
7 participants
Notifications
Total time spent: 20 minutes
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
infra/tickets#13280
No description provided.