Open Closed

Weird auth problem on opera and iphone browsers #1443


0
berkbadem created

I am trying to open my page in iframe with authentication. It works perfectly for chrome, mobile browsers etc. but its not working on opera and browsers on apple devices.

As i check browser prevents to set cookie after authentication.

My cors :

private void ConfigureCors(ServiceConfigurationContext context, IConfiguration configuration) { context.Services.AddAntiforgery(x => x.SuppressXFrameOptionsHeader = true); context.Services.AddCors(options => { options.AddPolicy(DefaultCorsPolicyName, builder => { builder .WithAbpExposedHeaders() .AllowAnyHeader() .AllowAnyMethod() .SetIsOriginAllowed(origin => true) .AllowCredentials(); }); }); }


13 Answer(s)
  • 0
    maliming created
    Support Team

    hi

    but its not working on opera and browsers on apple devices.

    Can you share the version info of browser?

  • 0
    berkbadem created

  • 0
    maliming created
    Support Team

    hi

    Can you take a look at this?

    https://community.abp.io/articles/patch-for-chrome-login-issue-identityserver4-samesite-cookie-problem-weypwp3n

  • 0
    berkbadem created

    Same problem persists after recommended fix

  • 0
    maliming created
    Support Team

    hi

    Can you test your browser via https://samesite-sandbox.glitch.me/ then share the results?

  • 0
    berkbadem created

    i tried to manipulate output cookie and i removed httponly and set SameSite to Unspecified still cookie not set

  • 0
    berkbadem created

    Opera on win 10x64 :

  • 0
    berkbadem created

    safari on ios :

  • 0
    berkbadem created

    Firefox on ios :

  • 0
    berkbadem created

    Brave on ios :

  • 0
    maliming created
    Support Team

    hi

    Can you add your browser's userAgent in DisallowsSameSiteNone(string userAgent) method?

    They does't recognize SameSite=None;

  • 0
    berkbadem created

    No luck, i even tried return true alwas but no luck.

  • 0
    maliming created
    Support Team

    i even tried return true alwas but no luck.

    What's is results now?

    https://samesite-sandbox.glitch.me/

    Can you share your website url and user&password with me? [email protected]