I am unable to authenticate with FP SSO when registering a warranty

I am attempting to modify the e-mail address of my warranty, so I visited shop.fairphone.com/warranty/start. Although I expect that shop.fairphone.com/warranty/device is the place to modify it, to first confirm that I registered it without my FP SSO connected, I visited shop.fairphone.com/web/login?redirect=/warranty/start:

Attempting to authenticate with my My Fairphone account redirects me to shop.fairphone.com/web/login?oauth_error=3, where I see:

You do not have access to this database or your invitation has expired. Please ask for an invitation and be sure to follow the link in your invitation email.

It’s not a SSO. Don’t waste your time trying to understand. If you change a pwd for support it doesn’t change for shop. You can sign out of the one but not the other in the same browser. Accounts for shop.f and support.f can be different. And of course for the forum but that’s normal to my mind.

What makes things even more complicated, to my mind, is that there’s no very obvious way to change the pwd for shop. Though you can, rather ignominiously, use the “forgotten password” option on the shop sign-in form.

I’ve already engaged in discussions about this and have given up trying to prove my point. Maybe it’s just a problem with my account(s) but it looks to me as though you’re seeing the same thing.

P.S. The account used in the MyFairphone app appears to be the one for shop.f rather than support.f which also strikes me as a bit odd.

@OldRoutard, that’s why I refer to it as SSO. Although it might not require LDAP in the backend, they appear to be distinct software packages.

I’m aware that my FP ZenDesk account isn’t bound to their SSO. That’s quite standard for ZenDesk accounts: the sole recent exception I’ve discovered (to an extent) is Dropbox’s. [1] If even Microsoft can’t with their Minecraft ZD instance, I doubt that FP can.


  1. reddit.com/r/dropbox/comments/sj1gej/comment/nng6q42 ↩︎

Well we’re more or less agreed :slightly_smiling_face:

  • shop.f and the MyFairphone app use the same account but require separate authentication
  • support.f uses a separate account with ZD so not on the same directory. It certainly ought to be possible, though depends on both ZD and FP having compatible authentication mechanisms. In my book, Microsoft isn’t a reference :wink:
  • forum is separate again, but for understandable reasons.

@OldRoutard, can you elaborate on this? That might be the source of my confusion, if true. I appear to be able to utilise my shop.fairphone.com at both that domain, and com.fairphone.myfairphone. They’re bound by authentication.fairphone.com SSO.

Actually, Discourse supports LDAP and OAuth2 SSO. I don’t understand why it’s not.

I think because not administered by the same people at all. The forum is kept quite separate from other services.

Make sure you’ve logged out of com.fairphone.myfairphone before trying to log in to shop.f (just an idea).

@OldRoutard, the installed APKs WebView’s session storage, versus org.mozilla.fenix’s, are separate – they should merely appear to the website as separate browsers. After all, the website can’t know whether a valid CSRF token exists until I attempt to log in, so it shouldn’t matter.