Coder Social home page Coder Social logo

Comments (5)

sven-borkert avatar sven-borkert commented on September 17, 2024 1

(But lots of thanks for this nice sample application, it's very useful for learning and understanding :) )

from sample-angular-oauth2-oidc-with-auth-guards.

sven-borkert avatar sven-borkert commented on September 17, 2024

Update/Solved:

This seems to be caused by uBlock Origin in my Firefox. I'll try to find out some more details about it.

from sample-angular-oauth2-oidc-with-auth-guards.

jeroenheijmans avatar jeroenheijmans commented on September 17, 2024

Thanks for sharing the root cause, that might help others find this issue and a solution!

I'll close the issue but feel free to add any other details for others to find.

from sample-angular-oauth2-oidc-with-auth-guards.

sven-borkert avatar sven-borkert commented on September 17, 2024

Hi,

I could not find out what uBlock Origin blocks exactly to break this mechanism, but it's easy reproducible that it does. It does not show anything blocked in the overview and the network request protocol.

I also noticed that enabling the "Enhanced Tacking Protection" in Firefox also breaks the silent refresh in the same way.

It seems to me that this refresh mechanism with the hidden iframe is likely to be blocked by anti tracking tools, so this mechanism is not very safe to use as it might not work for many users? Do you have any opinion on that?

Regards,
Sven

from sample-angular-oauth2-oidc-with-auth-guards.

jeroenheijmans avatar jeroenheijmans commented on September 17, 2024

Glad to hear the sample is useful!

The third party cookie blockades are certainly something that messes with the iframe-based silent refresh mechanism. You can read my "SPA Necromancy" blogpost for extensive details, or a smaller version in the repo's readme.

from sample-angular-oauth2-oidc-with-auth-guards.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.