Spartacus - Expired Token sent along with basesites API call breaks storefront load

Viewed 61

We have an issue with Spartacus B2B 4.2 running with CSR and early login enabled that after the oauth token expires and user opens the website, a blank page is displayed.

Here goes the scenario to simulate:

  1. User logs in succesfully
  2. Then, Spartacus stores the oauth token in the localstorage
  3. User closes the application and/or the browser
  4. Next day, user returns to the website.
  5. Spartacus calls the basesites API and sends along with the request the expired token
  6. This last call fails, Spartacus cannot figure the website and nothing is rendered - blank page displayed.
  7. Now, if user refreshes the page, token is not longer sent and the page is loaded succesfully.

We don't have customizations to the authentication module in our project.

General information:

  1. This is Spartacus B2B App
  2. Version 4.2
  3. Running CSR
  4. Early login is enabled (https://sap.github.io/spartacus-docs/early-login/)

We do have another Spartacus B2C App, running same version, but with SSR, that the error doesn't happen.

So, my questions are:

  1. Is this a bug in the version?
  2. Why Spartacus is not leveraging OAuth Refresh token returned during the login process? According to https://sap.github.io/spartacus-docs/session-management/, "When a request fails because the access token has expired, the interceptor uses the refresh token (if it exists) to request a new access token, and then retries the failed request with the new token."
  3. Is there any configuration that we should review?

Thanks,

Adriano

0 Answers
Related