使用oidc-client.js遇postMessage跨域源不匹配错误,单用户受影响求助
使用oidc-client.js遇到跨origin postMessage错误的排查问题
错误日志:
oidc-client.min.js:1 Failed to execute 'postMessage' on 'DOMWindow': The target origin provided ('https://auth.xxx.yyy.co.uk') does not match the recipient window's origin ('https://xxx.yyy.co.uk').
其中https://auth.xxx.yyy.co.uk是Identity Server地址,https://xxx.yyy.co.uk是SPA应用地址。
目前遇到的情况:
- 该错误仅影响单个用户,排除CSP配置问题(若为CSP问题会影响所有用户)
- 受影响用户会陷入SPA与身份服务器之间的重定向循环
- 已排查点:和用户共享屏幕未发现浏览器设置差异,双方使用同一版本Chrome;尝试过无痕窗口访问,身份服务器的自动发现响应全部正常;注意到该用户网络速度极慢,但用Chrome的慢3G模拟环境未能复现问题(怀疑是静默续期在登录重定向完成前触发的时序问题)
- 其他所有用户均能正常登录,项目启用了silent-renew功能,推测该错误由iframe回调身份服务器时触发
想问问有没有人遇到过类似问题?
我的oidc-client配置:
const config = { authority:xxxx, client_id:xxx, redirect_uri:xxx, response_type: 'code', scope: 'openid profile api', post_logout_redirect_uri:xxx, automaticSilentRenew: true, silent_redirect_uri:xxx, clockSkew: 3600, //60 minutes, userStore: new WebStorageStateStore({ store: window.localStorage }), }; Log.logger = console; Log.level = Log.DEBUG; const userManager = new UserManager(config);
组件中的相关代码:
getUser().then((user) => { if (!user || user.expired) { signinRedirect(`${location.pathname}${location.search}`).catch( (e) => { history.push('/Access-Denied'); } ); } else { storeUser(user); }
内容的提问来源于stack exchange,提问作者Alex Driver
相关产品推荐
相关产品推荐

