Yii2 Bad Request 400 - Unable to login from iframe on another domain

Viewed 1340

I am using iframe on domain1.com And the yii2 web app is on domain2.com

I am have passed domain.com url in the src of iframe on domain1.com and use this in the yii2 Access-Control-Allow-Origin: * to enable cors

I can login on domain2.com but it throws bad request 400 error if I try logging in through iframe on domain1.com

Any help would be really appreciated

2 Answers

Here is the answer to my question, I solved the problem

  • Change the PHP version to >7.3
  • Go into the config/web.php for basic app or config/main.php
  • Add this: 'httpOnly' => true, 'secure' => true, 'samesite' => 'None' in _csrf param for request block and _identity cookie in the user block

Using this you would be able to log into the domain1.com and domain2.com using same session on both the domains if the site is in iframe in the domain1.com

For the PHP version < 7.3, Update the main.php config file and set the value of sameSite to None in variable path as
- cookie

    identityCookie' => [
           'name' => 'your_cookie_name',
           'httpOnly' => true
           'path' => '/;SameSite=None',
           'secure' => true
       ]
    
- session-cookie  

    'cookieParams' => [
      'lifetime' => time()*60,
      'httpOnly' => true,
      'secure'=>true,
      'path' => '/;SameSite=None'
    ]
    

Note:

  1. You may need to edit the file: yii\web\Cookie, by updating the value of $path from '/' to '/;SameSite=None'.
  2. PHP 7.3 and YII 2.0.21 comes with the solution of SameSite with 3 values Lax,Strict and None. Click here to know more.
Related