Unable to sign out of FieldMaps - SAML & Android.

1670
15
03-31-2023 02:21 AM
VickyS
by
Occasional Contributor

Hi

Has anyone else had issues signing out of Field Maps with SAML authentication enabled in ArcGIS Enterprise? I can sign in and sign out but then if I tap 'sign in' again I am logged straight back in without being prompted for my credentials. Essentially we cannot switch users. 

We have just installed ArcGIS Enterprise 11.0 and set up SAML authentication.  FieldMaps on Android is not letting users sign out unless we clear the cookies from the browser. We are using Android 11 and FieldMaps 23.1.1. It works on iOS devices.

@ColinLawrence - Have you come across this before?  It would be useful to know if it is a bug or a issue with our system set up. 

Thank you

15 Replies
VickyS
by
Occasional Contributor

Hello @ColinLawrence 

Can you provide an update on this and reply to @AnthonyJonesRSK

Our field users are understandably frustrated.  What is ESRI's plan to address this bug? When will it be fixed? Will FieldMaps be developed to support android shared device mode?

Is there anyone else we can contract to gain support for this? I have had the same response as Anthony from ESRI UK support.

Thank you

0 Kudos
VickyS
by
Occasional Contributor

That's very helpful thank you. I will ask ESRI UK support to do as you suggest. 

It would be useful if the FieldMaps /Collector documentation included this bug as it is business critical if you depend on editor tracking and use shared devices.

0 Kudos
PegGronemeyer1
New Contributor III

I was running into similar problems...So if I am understanding correctly, for a survey with multiple users, each user is going to constantly have to clear their browser cache on their device?  I'm hoping that I am very wrong.  Any update on this?

0 Kudos
VickyS
by
Occasional Contributor

Yes users have to clear the browser history.  I logged a support call with ESRI UK and they have given me a bug reference.  There is no update on whether or not it will be fixed. If you log a support call it may add some weighting to the issue.

BUG-000144885: When working with the user's own identity provider (IDP) in the ArcGIS Field Maps mobile app, SAML logins are cached, preventing a new user from logging in when a previous user logs out.

BUG-000144885 for ArcGIS Field Maps (esri.com)

The workaround for it is currently the following steps:

  1. Log in to ArcGIS Field Maps on the mobile device through the SAML login.
  2. Log out of the mobile app.
  3. Clear the browser history.
  4. Logging in now prompts for credentials, and another user can log in and use the ArcGIS Field Maps mobile app.

This workaround is only possible if there is a browsing history to clear.

We have also blocked access to Office365 apps on shared devices until this is rectified which far from ideal.

0 Kudos
PegGronemeyer1
New Contributor III

Thank you so much for the quick answer

0 Kudos
ColinLawrence
Esri Regular Contributor

Hopefully I can provide some context as understandably there are frustrations around this issue. I am by no means an authentication expert so please excuse if I misspeak slightly. Ultimately, this comes down to an issues with the Browser's (Chrome or chromium) caching behavior. Chrome does not by default allow private sessions when authenticating, and therefore the application will use existing cookies in the sign in process.  When signing out of the app, we tear down the applications state but cannot tear down the browser cookie. We are investigating a workaround to allow users to authenticate regardless of browser state which should alleviate this problem. 

Regards,
Colin
0 Kudos