Flutter Auth on iOS hangs when retrieving token with code exchange

Viewed 883

I have the following code in flutter trying to retrieve an oauth2 token via auth code with PKCE flow:

final FlutterAppAuth appAuth = FlutterAppAuth();

final request = AuthorizationTokenRequest(
    B2C_CLIENT_ID,
    B2C_REDIRECT_URI,
    discoveryUrl: 'https://$B2C_DOMAIN/.well-known/openid-configuration',
    scopes: ['openid', 'profile', 'offline_access'],
    // promptValues: ['login']
);

final AuthorizationTokenResponse result =
    await appAuth.authorizeAndExchangeCode(request);

When this code is run in iOS, the browser opens and I can see it tries to load the signin page, but then immediately closes. No exceptions are thrown or anything. The code basically hangs at appAuth.authorizeAndExchangeCode almost like it doesn't know that the browser has closed.

I am not sure what could be causing this.

The code correctly determines the url for showing credentials using the discoveryUrl (i.e. it makes the http request first using the discoveryUrl) but not sure why it basically hangs after.

I am using azureb2c for authentication here.

Edit

Ok turns out this is a problem with using azure b2c in particular as tried it with a different identity provider and works fine.

I managed to locate the issue and fix it now a login page shows in the browser. After entering credentials, browser closes, but code still hangs on appAuth.authorizeAndExchangeCode(request); and does not proceed.

Also found existing issue. on github: https://github.com/MaikuB/flutter_appauth/issues/182

2 Answers

I managed to solve this following the below answer on the Github repository of the flutter_appauth plugin.

https://github.com/MaikuB/flutter_appauth/issues/182#issuecomment-840707729

Eventually, all I had to do was to add a trailing slash to the redirect url parameter in AuthorizationTokenRequest. (It looks like Azure AD appends on a trailing slash to the redirect url which causes the validation in AppAuth to fail).

My app worked correctly with the slash both on Android and iOS.

P.S. If this doesn't work for someone, try to adjust the redirect url in your App Registration as suggested in the respective thread https://github.com/MaikuB/flutter_appauth/issues/223.

I suspect this is related to the call to resumeExternalUserAgentFlow, so here is a plan of action for you:

  1. Follow the steps in my blog post to get the AppAuth Swift + Carthage sample working - which also uses a Private URI Scheme. Use my online configuration details as specified in the blog post and you should have a working solution. I have just verified that my instructions still work.

  2. Update the same sample to use your Azure AD configuration and see if it still works. If so then there is nothing wrong with AppAuth and the problem is in the Flutter layer.

  3. If the Swift sample fails when you update to Azure AD configuration, add some print messages for the URL being supplied to resumeExternalUserAgentFlow in the AppDelegate class, and see if this is different to the original redirect URI. If the redirect URIs are different, reset to the original value and hopefully that will resolve things.

Related