Frontify incident

SSO Login Issue

Notice Resolved View vendor source →

Frontify experienced a notice incident on September 29, 2021, lasting —. The incident has been resolved; the full update timeline is below.

Started
Sep 29, 2021, 03:45 PM UTC
Resolved
Sep 29, 2021, 07:00 AM UTC
Duration
Detected by Pingoru
Sep 29, 2021, 03:45 PM UTC

Update timeline

  1. resolved Sep 29, 2021, 03:45 PM UTC

    On September 29th a bug was reported that umlauts are not considered in group mapping, during the SSO login process. One of our developers fixed this bug, and, in order to verify the fix, he used some dummy credentials from his favourite show, SpongeBob. Unfortunately, the dummy credentials were shipped to production and affected the SSO login process. As a result, the wrong profile information was shown to already-registered users and the access to certain guidelines or projects was declined. Most importantly, no security breach happened and no external users had access to your account or your data. We rolled back the code and provided a fix shortly after that. We apologize for the circumstances. We learned our lesson from this and will analyze our deployment and peer programming process to avoid such mistakes in the future.