# Login causes "Bad Request"

**URL:** <https://discourse.openondemand.org/t/login-causes-bad-request/4723>\
**Category:** Get Help\
**Created:** [January 23, 2026, 5:16pm UTC](https://discourse.openondemand.org/t/login-causes-bad-request/4723 "2026-01-23T17:16:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![davide-q](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/davide-q/32/1510_2.png) [@davide-q](https://discourse.openondemand.org/u/davide-q)\
**Post date:** [January 23, 2026, 5:16pm UTC](https://discourse.openondemand.org/t/login-causes-bad-request/4723/1 "2026-01-23T17:16:27Z")

</div>

Suppose an user has an OnDemand session open in their browser, say at the page [https://example.com/pun/sys/dashboard/batch\_connect/sessions](https://example.com/pun/sys/dashboard/batch_connect/sessions)

Suppose the browser is also set with “remember open tabs” at restart. Then they close the browser, some time elapses and then they open their browser again.

The OnDemand tab, instead of reappearing at the previous URL, it goes (maybe by redirect?) to something like [https://example.com/dex/auth/ldap/login?back=&state=tvfabht5xgfcqezvlppordach](https://example.com/dex/auth/ldap/login?back=&state=tvfabht5xgfcqezvlppordach) but otherwise shows a normal login page. Suppose the user does not log in immediately, but wait for a while. Unfortunately, that becomes a broken login page: if an user logs in there they receive the following response

 ![image](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/7/733780cc0edd40abfa69a9a0d1f860a58a43c278.png)

and need to login again.

Is there a way to prevent this from happening? Many users don’t read the documentation asking them to go to a fresh [https://example.com/](https://example.com/) (which redirects to a “fresh” state) before the login, and then think OOD is down, and ask support questions about it, wasting both their time and support time.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [January 26, 2026, 3:43pm UTC](https://discourse.openondemand.org/t/login-causes-bad-request/4723/2 "2026-01-26T15:43:28Z")

</div>

Sorry, not really anything you can do. Authentication systems have timeouts for very good reasons so you can’t disable them or similar.

A quick glance at dex documentation seems to indicate that it doesn’t has any redirect capabilities here.

---

<div class="post-metadata">

**Author:** ![davide-q](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/davide-q/32/1510_2.png) [@davide-q](https://discourse.openondemand.org/u/davide-q)\
**Post date:** [January 26, 2026, 8:55pm UTC](https://discourse.openondemand.org/t/login-causes-bad-request/4723/3 "2026-01-26T20:55:36Z")

</div>

> [@jeff.ohrstrom](#):
>
> Authentication systems have timeouts for very good reasons so you can’t disable them or similar.

Agreed on that part.

From the symptom perspective, though, can’t we make the HTML of the login page include a javascript redirect to the home page with a frequency same or faster or the timeout, to prevent forcing the user to have to remember to do that? Or by the following you mean that it’s impossible from the OnDemand side without changing the source code of dex too?

> [@jeff.ohrstrom](#):
>
> A quick glance at dex documentation seems to indicate that it doesn’t has any redirect capabilities here.

After all that page does have the header and footer of OnDemand, so maybe there is way to inject that javascript?

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [January 27, 2026, 4:15pm UTC](https://discourse.openondemand.org/t/login-causes-bad-request/4723/4 "2026-01-27T16:15:43Z")

</div>

You can try that I guess. I suppose the javascript would have to read interpret the context of the page and then set `window.location.href`. Might could work, though you’d have to be careful not to redirect on good/valid pages too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex015/uploads/osc/original/2X/b/bae70bd0ed39a3ae769c2108155f4cb3e9da8385.png) [@system](https://discourse.openondemand.org/u/system)\
**Post date:** [July 26, 2026, 4:16pm UTC](https://discourse.openondemand.org/t/login-causes-bad-request/4723/5 "2026-07-26T16:16:10Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
