Skip to content

Chrome(PNA) /local development / iframe #2273

Description

Hello, my name is Zakhar, and I'm a frontend developer. My company implemented single sign-on (SSO) in a commercial product using your oidc-client-ts library. We encountered an issue updating the Chrome policy related to disallowing access from the local network to the private network via an iframe. We use silent_redirect_uri and automaticSilentRenew: true . During local development, a specific issue arises: CORS fails due to my product accessing my authorization resource through an iframe: Example domains: https://my-product.local.company.dev/ and https://authorization.company.dev.as/. As far as I understand, the browser detects my IP as local and blocks it when the request goes to a private repository. Are there any settings that can solve this problem? I'll attach a link to the official Chrome website below for information on this issue and possible solutions. Perhaps someone has already asked you this question. Thanks in advance for your reply.
ref: https://developer.chrome.com/blog/pna-permission-prompt-ot-end

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions