User1(Android) and User2(iOS) are logging into the mobile application. User1 successfully logs into the application. Later when user2 logs in, he sees User1's details. The request flows to the server in below structure: Mobile hybrid app (Cordova plugin, Temenos UXP) -> GTM -> LTM -> LBs ->DC1/2 server Is there any possibility that two sessions getting overlapped with user details (Local storage/Session storage getting mixed) ? Is there any possibility of data overlapping at the cookie/cache level ? User 1 (android) logs in and after few minutes user 2 (iOS) logs in, before user 2 (iOS) logs in, User 2 is able to see user 1 details. Is it somewhere needs to checked at OS/Web browser/Plugins/Dependencies other than session level ?
Search results for
ASWebAuthenticationSession cookie
1,295 results found
Selecting any option will automatically load the page
Post
Replies
Boosts
Views
Activity
Environment details: MacbookPro, Ventura 13.0.1 XCode 14.1 I’m trying to use ASWebAuthenticationSession to implement OAuth2 for a MacOS application. When Chrome is my default browser, starting a session crashes the application. When either Firefox or Safari are the default browser, starting a session launches Safari with the login page. After logging in, instead of redirecting back to the application and invoking my session handler, a 404 page is displayed. Also displayed is a banner near the top of the window, containing an open button and instructions: “Open in the MyApp app”. Clicking the button redirects back to the app, and the OAuth received by the application:continueUserActivity:restorationHandler: method that I implemented in NSAppDelegate for Universal links. My session handler never receives the OAuth response or an error. Is there a solution or workaround for this? Thanks for any help.
Hi! I'm facing the following issue in different versions of Safari: When removing cookies via PHP on log out of an application I can see that the Safari Developer Tools > Storage > Cookies (of the website) removes the cookies from the list. So my user cookie is no longer there as expected, all good. However, if I run document.cookie on the console or document.cookie.includes('user') I can see the cookie listed there. I would expect the document.cookie to be updated with the Storage tab as it happens on the other browsers. Does anyone know why is this happening? Is there anything special that must be done for Safari to remove the cookie from there? This behaviour is consistent in versions v14, v15 and v16 of Safari. Thank you for your time. Regards, Borja.
I also ran the command tool in the sanitized mode which produced the following output: ==16886==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x00016fc5a454 at pc 0x0001007609f4 bp 0x00016fc5a3c0 sp 0x00016fc59b48 WRITE of size 21 at 0x00016fc5a454 thread T0 #0 0x1007609f0 in scanf_common(void*, int, bool, char const*, char*)+0x624 (libclang_rt.asan_osx_dynamic.dylib:arm64e+0x1c9f0) #1 0x100760e68 in wrap_fscanf+0x9c (libclang_rt.asan_osx_dynamic.dylib:arm64e+0x1ce68) #2 0x10024395c in readIniFile nii_dicom_batch.cpp:8812 #3 0x1001a366c in main main_console.cpp:259 #4 0x1949fbe4c () Address 0x00016fc5a454 is located in stack of thread T0 at offset 52 in frame #0 0x100243780 in readIniFile nii_dicom_batch.cpp:8803 This frame has 2 object(s): [32, 52) 'Setting' (line 8809) <== Memory access at offset 52 overflows this variable [96, 351) 'Value' (line 8809) HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork (longjmp and C++ exceptions *
Topic:
App & System Services
SubTopic:
Core OS
Tags:
Thank you so much for your response endecotp. I think you are absolutely right about certificates and they cannot be used for authentication. I tried the way you told me but several headers like acn01, atsvric and dssid2 were missing from my cookies in browser. Eventually, I got the same error. I guess the way I am trying to automate the installation process is wrong and I need to download the required version of Xcode, have it saved on ftp server and then make all my machines to it and download. The downside of this approach is that Xcode itself is very heavy(about 9GB) so it will require several hours to download from another server to the target machines, which may not be the best way.
Topic:
Developer Tools & Services
SubTopic:
Xcode
Tags:
Here are the notes I wrote when I did this: XCode downloads are available from https://developer.apple.com/download/all/?q=xcode Example link: https://download.developer.apple.com/Developer_Tools/Xcode_13.1/Xcode_13.1.xip But these require dev programme membership; wgetting without cookies returns an HTML page. To get the required cookies, in Safari visit a truncated URL: https://download.developer.apple.com/Developer_Tools/ Do this with the Javascript console open. Select the network tab and copy the entire Cookie header (not the individual cookies). Now it's possible to wget on (a linux system): wget --header 'Cookie: s_fid=2B4119F75B4D610EB0-03724F1FC4C7A124C7; s_sq=awdappledeveloper%3D%2526pid%253Dall%252520-%252520downloads%252520-%252520apple%252520developer%2526pidt%253D1%2526oid%253Dhttps%25253A%25252F%25252Fdownload.developer.apple.com%25252FDeveloper_Tools%25252FXcode_13.1%25252FXcode_13.1.xip%2526ot%253DA; ADCDownloadAuth=knTCDvQAPHK4KPOjAT94Pc3FpNJ85Ual
Topic:
Developer Tools & Services
SubTopic:
Xcode
Tags:
Thank you so much for your response endecotp. I tried without certificates but got the same error. Here is how I tried but used cookies from google chrome instead of safari. Is there difference? wget https://download.developer.apple.com/Developer_Tools/Xcode_13.3.1/Xcode_13.3.1.xip --load-cookies=cookies.txt I created signing certificates that should have worked for logging to developer.apple.com - https://developer.apple.com/support/certificates
Topic:
Developer Tools & Services
SubTopic:
Xcode
Tags:
I’ve done this in the past: No certificates. Visit the site in Safari. Log in. Open the developer console. Extract the cookies. Pass the cookies to wget (maybe using —header). (I seem to recall doing something like modifying the URL to deliberately get an error page???) Of course that relies on cookies that will expire quite soon. It may not work for your situation. (what certificate exactly are you referring to?)
Topic:
Developer Tools & Services
SubTopic:
Xcode
Tags:
I submitted my app for review for the third time and it was rejected for the third time. This is cited as the reason for rejection. But I don't want to disable user login because I'm sure this will cause some security problems. How can I overcome this problem. Guideline 5.1.1 - Legal - Privacy - Data Collection and Storage We noticed that your app requires users to register or log in to access features that are not account based. Apps may not require users to enter personal information to function, except when directly relevant to the core functionality of the app or required by law. For example, an e-commerce app should let users browse store offerings and other features that are not account based before being asked to register, or a restaurant app should allow users to explore the menu before placing an order. Registration must then only be required for account-specific features, such as saving items for future reference or placing an order. Next Steps To resolve this issue, please revise your app to let us
Topic:
App Store Distribution & Marketing
SubTopic:
App Store Connect
Tags:
App Review
App Store Connect
App Submission
Hi everyone, I am trying to download Xcode from command line the following way: wget --certificate=certificate.pem --private-key=private-key.pem --server-response https://download.developer.apple.com/Developer_Tools/Xcode_13.3.1/Xcode_13.3.1.xip --no-check-certificate --load-cookies=cookies.txt I am getting the following error: HTTP request sent, awaiting response... 302 Moved Temporarily Location: https://developer.apple.com/unauthorized/ I have the certificate and private key from developer.apple.com and I am using them for authentication(correct me if I am wrong and they cannot be used for authentication). From several forums I found that the error regarding authorization could also be from cookies, so I got the cookies. Still the same error. I need the download of Xcode to be done from command line so that I can then automate the procedure using ansible playbooks (basically for the purpose of downloading and installing it on multiple mac machines.) Please, if the approach is ent
Topic:
Developer Tools & Services
SubTopic:
Xcode
Tags:
Forums Feedback
Xcode
Scripting
Sign in with Apple REST API
According to rfc-6265, The user agent will reject cookies unless the Domain attribute specifies a scope for the cookie that would include the origin server. but in iOS, I can save cookies even the Domain attribute is different to server. Below is my code for cookie in HTTPCookieStorage.shared.cookies ?? [] { HTTPCookieStorage.shared.deleteCookie(cookie) } let urlString = http://aa.bbb.net/bb/cc let cookie = HTTPCookie.cookies(withResponseHeaderFields: [Set-Cookie: key1=value1;Domain=baidu.com], for: URL(string: urlString)!) HTTPCookieStorage.shared.setCookie(cookie.first!) for cookie in HTTPCookieStorage.shared.cookies ?? [] { print(cookie) } let getCookie = HTTPCookieStorage.shared.cookies(for: URL(string: http://www.baidu.com/bb/cc)!) print(getCookie) In the above code, I can successfully get my cookie “key1=value1”,this should be wrong?What confuses me is how do I fix this?
Hi team, I'm troubleshooting some weird authentication issues within my website where I offer Signin with Apple option. Basically, after the user does Apple login, I have this script to update the location URI of the window opener back to my origin domain. But this line of the script is working correctly when login is launched in a browser such as Safari or Chrome, and it just got ignored when launched from a WebView within an application, and it can only be reproduced since iOS 15.5+. Here is some more context for comparison: Request from Safari: POST /callbackApple HTTP/1.1 Host: signin.example.com Content-Type: application/x-www-form-urlencoded Origin: https://appleid.apple.com Accept-Encoding: gzip, deflate, br Cookie: _ga=GA1.3.1679051778.1669664368; _gat=1; _gid=GA1.3.1808016405.1669664368; signin-cookie=5ce93a47904daa5e; _abck=F930E04300E8E8AB552C14541A40AD3C~0~YAAQmZTYF7CO3fCBAQAAZkOmHQha0qNYdbsfcZ4zEtwsjoRST+T+DNTMb5+E9uL8OvEL3YA0K0Tn7xS+OKoGPGib5rmpBOZVQq1+XoPEFJOij8Ao8mMKrvztGMN0H
Topic:
Safari & Web
SubTopic:
General
Tags:
WebKit
WebKit JS
Sign in with Apple REST API
Safari and Web
Facing the same issue on the 14. When I look at AudioStreamBasicDescription of the CMSampleBuffer that are received from videoChat mode on 14, I get this Optional( { mediaType:'soun' mediaSubType:'lpcm' mediaSpecific: { ASBD: { mSampleRate: 44100.000000 mFormatID: 'lpcm' mFormatFlags: 0xc mBytesPerPacket: 8 mFramesPerPacket: 1 mBytesPerFrame: 8 mChannelsPerFrame: 4 mBitsPerChannel: 16 } cookie: {(null)} ACL: {Mono} FormatList Array: { Index: 0 ChannelLayoutTag: 0x640001 ASBD: { mSampleRate: 44100.000000 mFormatID: 'lpcm' mFormatFlags: 0xc mBytesPerPacket: 8 mFramesPerPacket: 1 mBytesPerFrame: 8 mChannelsPerFrame: 4 mBitsPerChannel: 16 }} } extensions: {(null)} }) When I initialize audio session in default mode, the CMAudioFormatDescription of audio samples is Optional( { mediaType:'soun' mediaSubType:'lpcm' mediaSpecific: { ASBD: { mSampleRate: 44100.000000 mFormatID: 'lpcm' mFormatFlags: 0xc mBytesPerPacket: 2 mFramesPerPacket: 1 mBytesPerFrame: 2 mChannelsPerFrame: 1 mBitsPerChannel: 16 } cookie
Topic:
Media Technologies
SubTopic:
Audio
Tags:
I see 24 hours report completely broken and unreliable in AppStoreConnect Sales & Trends for more than a month. When I submit a complain, all they say is clear cookies and caches and restart the browser. Either the complain is not forwarded to engineering or engineering is not acknowledging the issue.
Safari looses session cookies, so after some time (15-30 minutes) I have to login again. This happens for all my synced tabs with iOS and happens even if I use only macOS. It’s very annoying because I have to login again in a lot of services, multiple times a day.