I'm trying to integrate my company's SSO to the web app I've developed. I'm using Angular in the frontend and Django as the backend.
In order to create the SAML request, I'm using OneLogin's python-saml. The flow for SSO is:
- The user sends a login request to the backend
- Backend creates redirected SAML request as a response
- Frontend redirects to SSO page(user has to select the entity he/she belongs to)
- SSO authenticates the user and sends a response to the backend
I'm able to create the SAML request but when the browser redirects to the SSO page, I get a CORS error:
Response to preflight request doesn't pass access control check: “No 'Access-Control-Allow-Origin' header is present on the requested resource”
But when I copy the SAML request from the Location header and open in the new tab, the SSO page loads, and I am able to select the entity.
I've looked at other apps which already have SSO integrated and I've found out the following differences in the SAML request headers (header : my app vs other app):
- Origin : null vs No Origin present
- sec-fetch-mode : cors vs navigate
- sec-fetch-dest : empty vs document
I'm not able to find a way to configure these headers in the OneLogin's library, so I'm not sure if these headers are the reason why I'm getting the cors error.
If I am missing out on something, kindly let me know. Help me understand why I am getting the error.
Thanks in advance.