I have been discussing this with the Crowd Support team; but would like to see if others observe the same behaviour (or if it is something I have misconfigured) and whether you consider it expected or a problem.
For this I am using two computers with Firefox and the Firebug add-on (to manipulate cookies). Stash authenticates against Crowd and uses SSO.
Test Procedure
On the first computer:
- Log in to Stash and navigate to a page in your Stash instance. Note down the URL for later.
- Open Firebug and go to the Cookies tab. Note down the crowd.token_key.
On the second computer:
- Open a Firefox instance (do not navigate to Stash, or any Crowd authenticated website).
- Open Firebug and go to the Cookies tab. Use Create Cookie to create the crowd.token_key you noted from the first computer.
- Type the direct URL you noted from the first computer...
With my implementation you gain access to Stash on the second computer without having to enter any passwords.
[Sorry, I don't seem to be able to attach any example images to the question]