We have an issue with Spartacus B2B 4.2 running with CSR and early login enabled that after the oauth token expires and user opens the website, a blank page is displayed.
Here goes the scenario to simulate:
- User logs in succesfully
- Then, Spartacus stores the oauth token in the localstorage
- User closes the application and/or the browser
- Next day, user returns to the website.
- Spartacus calls the basesites API and sends along with the request the expired token
- This last call fails, Spartacus cannot figure the website and nothing is rendered - blank page displayed.
- Now, if user refreshes the page, token is not longer sent and the page is loaded succesfully.
We don't have customizations to the authentication module in our project.
General information:
- This is Spartacus B2B App
- Version 4.2
- Running CSR
- Early login is enabled (https://sap.github.io/spartacus-docs/early-login/)
We do have another Spartacus B2C App, running same version, but with SSR, that the error doesn't happen.
So, my questions are:
- Is this a bug in the version?
- Why Spartacus is not leveraging OAuth Refresh token returned during the login process? According to https://sap.github.io/spartacus-docs/session-management/, "When a request fails because the access token has expired, the interceptor uses the refresh token (if it exists) to request a new access token, and then retries the failed request with the new token."
- Is there any configuration that we should review?
Thanks,
Adriano