Skip to content

Chrome(PNA) /local development / iframe #2273

@zakhar-samakhval-devreon

Description

Hello, my name is Zakhar, and I'm a frontend developer. My company implemented single sign-on (SSO) in a commercial product using your oidc-client-ts library. We encountered an issue updating the Chrome policy related to disallowing access from the local network to the private network via an iframe. We use silent_redirect_uri and automaticSilentRenew: true . During local development, a specific issue arises: CORS fails due to my product accessing my authorization resource through an iframe: Example domains: https://my-product.local.company.dev/ and https://authorization.company.dev.as/. As far as I understand, the browser detects my IP as local and blocks it when the request goes to a private repository. Are there any settings that can solve this problem? I'll attach a link to the official Chrome website below for information on this issue and possible solutions. Perhaps someone has already asked you this question. Thanks in advance for your reply.
ref: https://developer.chrome.com/blog/pna-permission-prompt-ot-end

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions