Overcome ITP or Third Party Cookies issues for SSO and silent login

Viewed 334

It is known, that WebKit's ITP and third-party cookies blocking is preventing common SSO techniques from working correctly. This is especially related to the so-called silent login feature of SSO when user gets automatically logged into a newly visited domain, that is connected to some authentication server with which she is already authenticated (has an active "global" session). I believe this is commonly implemented using a hidden iframe and a post-message.

It looks like major IAM providers has surrendered to these obstacles and just provide a limited functionality. As an example, Stack Exchange portals not only doesn't support silent logins, but can't even restore the session active on other portals when you click on a log-in button explicitly:

AskUbuntu can't restore the session active on StackOverflow

AskUbuntu can't automatically restore the session active on StackOverflow.

SO, my questions are:

1). Is it actually possible to overcome these limitations in implementing SSO and especially the silent login function without redirecting the entire browser window to the auth server? Is it possible to use XHR + CORS for this? Or maybe some other storage mechanism like LocalStorage, Cache API, Service Workers, etc to persist the session if cookies are disabled?

2). How does Google solve this issue with their google.com/youtube.com domains? It does look like they are reloading the entire application while restoring the global session, but this happens only when user is actually logged in with Google. In case when the user is not logged in, YouTube is not reloading itself. How do they detect if user has actually got a global session?

0 Answers
Related