Firebase authenthication with SAML Providers from Identity Platform is not working in Firefox

Viewed 179

We have the same issue with multiple SAML sso providers in multiple projects(incl. production), regular providers such as google work as expected. All other browsers except for Firefox also work.

Steps to reproduce:

  1. I've set up an "Identity Provider" in GCP "Identity Platform" called "{my-provider-id}".
  2. Calling firebase to authenticate:
import firebase from "firebase/compat/app";
import "firebase/compat/auth";

// ...

const SAMLProvider = new firebase.auth.SAMLAuthProvider({my-provider-id});
await firebase.auth().signInWithPopup(SAMLProvider);
  1. I enter my credentials and log in to {my-provider}
  2. I get redirected back to "https://{my-project}.firebaseapp.com/__/auth/handler" and this results in the following error: "Unable to process request due to missing initial state. This may happen if browser sessionStorage is inaccessible or accidentally cleared."

The same thing happens with another sso provider in our production project.

I have tried searching for the cause of this for several hours now and the fact that it is working in chrome, safari as expected leads me to think this might be an issue with firebase auth and not our own end, please do advise how to troubleshoot this further or whether this is something you can reproduce on your end as well. Thank you

1 Answers

I had a similar issue with a few internal websites I use for work. This resulted in the constant redirects between {website}.firebaseapp.com and the actual website URL after performing a login attempt.

I found out that disabling Enhanced Tracking Protection for those websites in Firefox resolved the issue for me.

https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop?#w_what-to-do-if-a-site-seems-broken

The switch that disables the protection can be found by clicking the shield at the beginning of the address bar. Here is how it looks like:

How the switch looks

Related