4 ms·
You don't need a shared storage if you do SSO the right way. Just redirect with a session token. And if the SSO server wants to share state with the other serv
by pyentropy 6y ago
You don't need a shared storage if you do SSO the right way. Just redirect with a session token.
And if the SSO server wants to share state with the other services, like forcing a logout on a specific app, it can always do it on the server side (app backend <-> SSO backend with user token).
- cameronh90 6y agoSure and that is how we do SSO (though SameSite=Strict can interfere with that method too). But if that's the recommended approach, why are they providing a standard route to do SSO via an iframe with the Storage Access API? Does that API have any other valid uses that aren't tracking or SSO related?
- deleted 6y ago[deleted]
- pyentropy 6y agoIf the SSO system is legacy and must use cookies, then to request access for cookies you need to call requestStorageAccess() in a frame hosted on the origin, which will open a prompt asking the user to allow such cookie access.