Uploaded image for project: 'Nuxeo Enhanced Viewer'
  1. Nuxeo Enhanced Viewer
  2. NEV-327

ARender Previewer should set Cookie compatible with the iframe integration

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved
    • Priority: Minor
    • Resolution: Fixed
    • Affects Version/s: 10.3.0
    • Fix Version/s: 10.3.1
    • Component/s: Nuxeo Connector
    • Tags:
    • Browser:
    • Team:
      PLATFORM
    • Sprint:
      nxplatform #18
    • Story Points:
      1

      Description

      While deploying the 10.3.0 to Openshift, we've noticed that the authentication part wasn't working correctly, we ended on an Invalid Credentials error when browsing back to the previewer after the OAuth2 challenge.

      This was due to a blocked cookie by the browser because the Set-Cookie header from the previewer response does declare Same-Site: Lax and doesn't declare Secure.
      As ARender Previewer is integrated into an iframe inside Nuxeo, the header should declare Same-Site=none; Secure to be accepted by a modern browser.

        Attachments

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 2 hours
                  2h