You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用oidc-client.js遇postMessage跨域源不匹配错误,单用户受影响求助

使用oidc-client.js遇到跨origin postMessage错误的排查问题

错误日志:oidc-client.min.js:1 Failed to execute 'postMessage' on 'DOMWindow': The target origin provided ('https://auth.xxx.yyy.co.uk') does not match the recipient window's origin ('https://xxx.yyy.co.uk').

其中https://auth.xxx.yyy.co.uk是Identity Server地址,https://xxx.yyy.co.uk是SPA应用地址。

目前遇到的情况:

  • 该错误仅影响单个用户,排除CSP配置问题(若为CSP问题会影响所有用户)
  • 受影响用户会陷入SPA与身份服务器之间的重定向循环
  • 已排查点:和用户共享屏幕未发现浏览器设置差异,双方使用同一版本Chrome;尝试过无痕窗口访问,身份服务器的自动发现响应全部正常;注意到该用户网络速度极慢,但用Chrome的慢3G模拟环境未能复现问题(怀疑是静默续期在登录重定向完成前触发的时序问题)
  • 其他所有用户均能正常登录,项目启用了silent-renew功能,推测该错误由iframe回调身份服务器时触发

想问问有没有人遇到过类似问题?

我的oidc-client配置:

const config = {
  authority:xxxx,
  client_id:xxx,
  redirect_uri:xxx,
  response_type: 'code',
  scope: 'openid profile api',
  post_logout_redirect_uri:xxx,
  automaticSilentRenew: true,
  silent_redirect_uri:xxx,
  clockSkew: 3600, //60 minutes,
  userStore: new WebStorageStateStore({ store: window.localStorage }),
};
Log.logger = console;
Log.level = Log.DEBUG;
const userManager = new UserManager(config);

组件中的相关代码:

getUser().then((user) => {
        if (!user || user.expired) {
          signinRedirect(`${location.pathname}${location.search}`).catch(
            (e) => {
              history.push('/Access-Denied');
            }
          );
        } else {
          storeUser(user);
        }

内容的提问来源于stack exchange,提问作者Alex Driver

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 23:50:29