Widget with persistent user session across different websites

Viewed 119

I need to develop a widget, like a banner, that can be embedded in different websites. The user can register/login via the widget, and the user session should be persisted when the user visits another website containing this banner.

One way to do it is to include the banner via iframe in those browsers. However, this is becoming increasingly due to the ever-stricter third-party cookie policies implemented by modern browsers.

Of course, the banner can be embedded in the website in a div, and I could store the session token cookie under the domain of the website (as opposed to the domain of the widget/banner), but then this token would not be accessible when visiting from another website.

What are modern strategies/approaches to achieve the above?

1 Answers

I have a similar situation myself with what I'm working on, so I just wanted to post what I've learned so far to help other people looking at this question!

The app I'm working on is a plugin widget that is embedded in other websites. And, we're working on the ability to allow users to log into our service via our widgets and have a session that persists on partnered website(s). So, users would be at partner-site.com, log into our service hosted at api.our-plugin.com from partner-site.com, and then have a persistent session with api.our-plugin.com while they are using our widget on partner-site.com. I suppose my specification is a subset of yours, but if I were able to even have sessions across the partner domains, like partner-site-1.com and partner-site-2.com ... partner-site-N.com, that would be even better.

As for the answer, there is bad news. Well... Bad for widget developers, but good for end-users!

WebKit/Safari (which accounts for a majority of mobile users in the US), has completely blocked third-party cookies,
https://webkit.org/blog/10218/full-third-party-cookie-blocking-and-more/

So, I'm looking into how to work with these latest security standards!

It looks like there are solutions, but unfortunately, they don't seem as trivial as plain old cookies: https://auth0.com/docs/login/cross-origin-authentication
^ I think this one suggests hosting a new app under the same domain as every single third-party domain. But, obviously, it makes no sense at all for web widget developers to setup new servers for each partnering website that wants to install the widget on their website... That would be as if an app development team had to setup a new server for every single person who installed their app to their phone. Obviously, that makes no sense.

I'll post my findings/updates!

UPDATE:
It seems as though the future-proof options are either to use an iframe for the widget or to use a webworker. I think the underlying idea for each of these ideas is some means of "isolation".

Related