How to achieve cross domain SSO given that third party cookies are disabled by default in browsers?

Viewed 333

I am trying to work on a cross-domain SSO. I have a single central auth domain and couple of other domains (not sub domains. these are completely different ). Once you click on login, you should be taken to the central auth domain, and tokens should be set there either in localStorage or cookies, either is fine. The problem is getting the tokens on the other domains.

Could you help me with how google is able is set token on youtube.com without ever visiting or redirecting to it? Follow this to understand what I mean,

  • Open youtube.com in one tab and checkout its cookies tab.
  • Open accounts.google.com in another tab and checkout its cookies tab. (notice there are cookies for accounts.youtube.com, which means there is an iframe for accounts.youtube.com on accounts.google.com. Ignore this point for now, more on this later)
  • Login with credentials on accounts.google.com (notice it did not visit/redirect to youtube.com even once)
  • Come back to tab with youtube.com and refresh its cookies, you will see a bunch of new cookies set.

How is accounts.google.com able to set cookies for youtube.com? I could see that accounts.google.com has an iframe for accounts.youtube.com but how is accounts.google.com able to set cookies on the iframe. I tried the exact same setup as well, ie, open my real app in an iframe in SSO domain and after login try to set the cookie on the real app and redirect but on trying to set cookie, nothing happens. No error, nothing. If I disable the third-party cookie protection, I am able to set the cookie. How is google achieving this feat even with third-party cookies disabled?

I tried 2 approaches but both fail. 1)Approach 1I tried opening an iframe of this central auth in my real app and getting info from cookie and localStorage but both don't work, they just return null when in an iframe. (it works if i disable the third-party cookie protections)

  1. Approach 2I tried a setup same as google login flow as well, ie, open my real app in an iframe in SSO domain and after login try to set the cookie on the real app and redirect but on trying to set cookie, nothing happens. No error, nothing.

If I disable the third-party cookie protection, I am able to set the cookie in both approaches. How is google achieving this feat even with third-party cookies disabled?

0 Answers
Related