Infinite loop in Azure AD authentication when used with Angular service worker

Viewed 446

I have an Angular PWA that is hosted on Azure's app service and I'm using the default authentication that the app service provides with HTTP 302 found redirect for unauthenticated requests.

This auth seems to work correctly when the user logs in for the 1st time (or until the service worker is loaded/disabled). When the user logs in for the 2nd time (after the 1st session is timed out / logs out and back in) he is repeatedly redirected to the login.microsoftonline.com/<tenant>/oauth2/authorize?... page and after few tries, I get the following error on the console

Access to fetch at 'https://login.windows.net/<tenant>/oauth2/authorize?response_type=id_token&redirect_uri=https%3A%2F%2Fmy-site.azurewebsites.net%2F.auth%2Flogin%2Faad%2Fcallback&client_id=<cid>&scope=openid+profile+email&response_mode=form_post&nonce=34f9eab3fd89468cbe18a77dc0e73a75_20210407124243&state=redir%3D%252Fngsw.json%253Fngsw-cache-bust%253D0.7541325470022122' (redirected from 'https://my-site.azurewebsites.net/ngsw.json?ngsw-cache-bust=0.7541325470022122') from origin 'https://my-site.azurewebsites.net' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. If an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled.

I've also noticed that the service worker removes/changes some headers in the /.auth/login/aad/callback callback post-authentication:

Without Service Worker:

Request headers:
Host: my-site.azurewebsites.net 
Origin: https://login.microsoftonline.com
Referer: https://login.microsoftonline.com/

Response headers:
Location: https://my-site.azurewebsites.net/

With Service Worker:

Request headers:
Host: login.windows.net
Origin: <not there>
Referer: https://login.microsoftonline.com/

Response headers:
Location: https://login.microsoftonline.com/<tenant>/oauth2/authorize?response_type=id_token&redirect_uri=https%3A%2F%2Fmy-site.azurewebsites.net%2F.auth%2Flogin%2Faad%2Fcallback&client_id=<cid>&scope=openid+profile+email&response_mode=form_post&nonce=ed3797c5c85b4f1080faa31f3b597742_20210407085453&state=redir%3D%252F

As my issue looked very similar to this issue, I've added "navigationRequestStrategy": "freshness" in my service worker config but that did not work either. I'm not able to figure out the reason for this infinite loop, is there something I'm missing here?

0 Answers
Related