Identity Server 4 and SameSite cookie issue in Chrome 8

Viewed 942

I have an angular app that is using silent refresh using Identity Server 4 and the angular-auth-oidc-client package. So this means I'm affected by the SameSite Cookie issue as described at https://www.thinktecture.com/en/identity/samesite/prepare-your-identityserver.

So I applied the fix exactly as was described in the article.

Locally (localhost) it all works fine. I can log in, and if I hit F5, I remain logged in correctly:

Auth result received AuthorizationState:authorized validationResult:Ok

However, when deployed to azure, I still get the warning in chrome:

enter image description here

I can log in the first time, but if I then hit F5, I'm nog logged in anymore:

Auth result received AuthorizationState:unauthorized validationResult:LoginRequired

Do you have any idea what could still be the issue? If I try this with Firefox or edge, there is no problem.

1 Answers

I finally found the issue, and it was in fact not an issue with the code. I test a lot in chrome's incognito mode, but then by default third party cookies are refused. Obviously this means that authentication did not work properly. In normal mode it works fine. If I enable third party cookies in incognito mode, it also works again.

Related