Search results for

ASWebAuthenticationSession cookie

1,295 results found

Post

Replies

Boosts

Views

Activity

macOS SSO extension runs into a loop in redirect
Hi, I created an SSO extension that works fine. The extension triggers for my domain when I need to run an OIDC flow by the authorize path of my issuer. I finish the whole OIDC flow inside the extension and get the required parameters (access token, ID token, state, etc.), and build the Location header to return to the caller (in my case it triggers from Safari). I also attach the Set-Cookie with my cookies. For completion, I call the authorizationRequest?.complete(httpResponse: response, httpBody: nil) with a 302 code response I create which contains the cookies and the Location header. My problem is that the Safari gets the response with the redirect, removes the Extension, and a sec after the extension triggers again with the same authorize request. All this happens in a loop without stopping, unless I call authorizationRequest?.doNotHandle(). I checked the Location header to a similar one from a regular web flow that works fine (without the extension) and both are the same. Any
2
0
1.3k
Jan ’23
NSURLSession single sign on cookie missing in Watchkit2
we encountered a strange problem when using NSURLSession with watchkit 2, ios 9.0.most headers and cookies are returned from the server (using HTTPS)but the single sign on cookie is missingwhen running the exact same code in an iphone application (request via NSURLSession) the cookie is visible in the shared cookie storage.I've read alot of posts on how to add headers via the HTTPAdditionalHeaders, but this specific cookie should have been returned from the serverwhy would one specific cookie go missing while the others are returned?
3
0
1.5k
Jan ’23
Session data overlapping
User1(Android) and User2(iOS) are logging into the mobile application. User1 successfully logs into the application. Later when user2 logs in, he sees User1's details. The request flows to the server in below structure: Mobile hybrid app (Cordova plugin, Temenos UXP) -> GTM -> LTM -> LBs ->DC1/2 server Is there any possibility that two sessions getting overlapped with user details (Local storage/Session storage getting mixed) ? Is there any possibility of data overlapping at the cookie/cache level ? User 1 (android) logs in and after few minutes user 2 (iOS) logs in, before user 2 (iOS) logs in, User 2 is able to see user 1 details. Is it somewhere needs to checked at OS/Web browser/Plugins/Dependencies other than session level ?
2
0
758
Dec ’22
App Tracking Transparency and Cookies
I'm using a webview for the UI of my application, this uses a cookie for the login process. This cookie is only for handling the login and isn't used for advertising, tracking or sharing with third parties. My store submission is failing because the application doesn't show the App Tracking Transparency prompt. My understanding from reading the documentation is this is required if you're tracking the user through multiple apps/websites and/or passing that data to third parties or for targeted advertising. The application does none of these things, therefore from the documentation I shouldn't need to show the App Tracking Transparency prompt. Is it the case that the use of cookies at any point for any reason within a web view within an application require the use of the App Tracking Transparency prompt, as I feel this should have been highlighted within the documentation if this is the case?
5
0
5.9k
Dec ’22
Is ATT required for launching out to web?
My app was recently rejected because of non-compliance with App Tracking transparency because, while I do not use any kind of tracking in my app whatsoever, I do link out to the website that my company owns, and on that site, there are cookies. I obviously cannot control what the website does as I'm not on that team. Is there any way to launch a website that uses cookies without requiring the ATT popup? I've heard that SFSafariViewController is sufficient but WKWebview is not. Is this true? Is there something I can do to launch to the website (for things like FAQs) but avoid requiring the ATT popup?
8
0
12k
Dec ’22
Safari crashing iOS 14
Safari has been working fine since Monday. Here we are 6 days later and Safari on my iPhone wont load any websites without crashing. The app itself doesnt crash, just the tab crash's. Says problem repeatedly happened on this webpage and page title changes to Webpage Crashed. I have cleared all cookies and data, rebooted phone several times, perform force reboot/reset. I'm kind of surprised that I'm the only one reporting this issue.
29
0
20k
Dec ’22
Reply to zsh: abort <tool_name>
I also ran the command tool in the sanitized mode which produced the following output: ==16886==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x00016fc5a454 at pc 0x0001007609f4 bp 0x00016fc5a3c0 sp 0x00016fc59b48 WRITE of size 21 at 0x00016fc5a454 thread T0 #0 0x1007609f0 in scanf_common(void*, int, bool, char const*, char*)+0x624 (libclang_rt.asan_osx_dynamic.dylib:arm64e+0x1c9f0) #1 0x100760e68 in wrap_fscanf+0x9c (libclang_rt.asan_osx_dynamic.dylib:arm64e+0x1ce68) #2 0x10024395c in readIniFile nii_dicom_batch.cpp:8812 #3 0x1001a366c in main main_console.cpp:259 #4 0x1949fbe4c () Address 0x00016fc5a454 is located in stack of thread T0 at offset 52 in frame #0 0x100243780 in readIniFile nii_dicom_batch.cpp:8803 This frame has 2 object(s): [32, 52) 'Setting' (line 8809) <== Memory access at offset 52 overflows this variable [96, 351) 'Value' (line 8809) HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork (longjmp and C++ exceptions *
Topic: App & System Services SubTopic: Core OS Tags:
Dec ’22
Reply to Download Xcode from command line
Thank you so much for your response endecotp. I think you are absolutely right about certificates and they cannot be used for authentication. I tried the way you told me but several headers like acn01, atsvric and dssid2 were missing from my cookies in browser. Eventually, I got the same error. I guess the way I am trying to automate the installation process is wrong and I need to download the required version of Xcode, have it saved on ftp server and then make all my machines to it and download. The downside of this approach is that Xcode itself is very heavy(about 9GB) so it will require several hours to download from another server to the target machines, which may not be the best way.
Dec ’22
Download Xcode from command line
Hi everyone, I am trying to download Xcode from command line the following way: wget --certificate=certificate.pem --private-key=private-key.pem --server-response https://download.developer.apple.com/Developer_Tools/Xcode_13.3.1/Xcode_13.3.1.xip --no-check-certificate --load-cookies=cookies.txt I am getting the following error: HTTP request sent, awaiting response... 302 Moved Temporarily Location: https://developer.apple.com/unauthorized/ I have the certificate and private key from developer.apple.com and I am using them for authentication(correct me if I am wrong and they cannot be used for authentication). From several forums I found that the error regarding authorization could also be from cookies, so I got the cookies. Still the same error. I need the download of Xcode to be done from command line so that I can then automate the procedure using ansible playbooks (basically for the purpose of downloading and installing it on multiple mac machines.) Please, if the approach is ent
4
0
4.1k
Dec ’22
Reply to Download Xcode from command line
Here are the notes I wrote when I did this: XCode downloads are available from https://developer.apple.com/download/all/?q=xcode Example link: https://download.developer.apple.com/Developer_Tools/Xcode_13.1/Xcode_13.1.xip But these require dev programme membership; wgetting without cookies returns an HTML page. To get the required cookies, in Safari visit a truncated URL: https://download.developer.apple.com/Developer_Tools/ Do this with the Javascript console open. Select the network tab and copy the entire Cookie header (not the individual cookies). Now it's possible to wget on (a linux system): wget --header 'Cookie: s_fid=2B4119F75B4D610EB0-03724F1FC4C7A124C7; s_sq=awdappledeveloper%3D%2526pid%253Dall%252520-%252520downloads%252520-%252520apple%252520developer%2526pidt%253D1%2526oid%253Dhttps%25253A%25252F%25252Fdownload.developer.apple.com%25252FDeveloper_Tools%25252FXcode_13.1%25252FXcode_13.1.xip%2526ot%253DA; ADCDownloadAuth=knTCDvQAPHK4KPOjAT94Pc3FpNJ85Ual
Dec ’22
Reply to Download Xcode from command line
Thank you so much for your response endecotp. I tried without certificates but got the same error. Here is how I tried but used cookies from google chrome instead of safari. Is there difference? wget https://download.developer.apple.com/Developer_Tools/Xcode_13.3.1/Xcode_13.3.1.xip --load-cookies=cookies.txt I created signing certificates that should have worked for logging to developer.apple.com - https://developer.apple.com/support/certificates
Dec ’22
Apple Release Issues
I submitted my app for review for the third time and it was rejected for the third time. This is cited as the reason for rejection. But I don't want to disable user login because I'm sure this will cause some security problems. How can I overcome this problem. Guideline 5.1.1 - Legal - Privacy - Data Collection and Storage We noticed that your app requires users to register or log in to access features that are not account based. Apps may not require users to enter personal information to function, except when directly relevant to the core functionality of the app or required by law. For example, an e-commerce app should let users browse store offerings and other features that are not account based before being asked to register, or a restaurant app should allow users to explore the menu before placing an order. Registration must then only be required for account-specific features, such as saving items for future reference or placing an order. Next Steps To resolve this issue, please revise your app to let us
1
0
806
Dec ’22
Reply to Download Xcode from command line
I’ve done this in the past: No certificates. Visit the site in Safari. Log in. Open the developer console. Extract the cookies. Pass the cookies to wget (maybe using —header). (I seem to recall doing something like modifying the URL to deliberately get an error page???) Of course that relies on cookies that will expire quite soon. It may not work for your situation. (what certificate exactly are you referring to?)
Dec ’22