Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Social Sign In with Apple as Provider #414

Open
5 tasks done
vafokroy opened this issue Feb 5, 2025 · 1 comment
Open
5 tasks done

Social Sign In with Apple as Provider #414

vafokroy opened this issue Feb 5, 2025 · 1 comment
Assignees
Labels
bug Something is not working.

Comments

@vafokroy
Copy link

vafokroy commented Feb 5, 2025

Preflight checklist

Ory Network Project

No response

Describe the bug

If you configure Apple as a social sign-in provider in Ory Network, you will receive a fixed domain as redirect_uri that looks something like this:

https://<KRATOS_DOMAIN>/self-service/methods/oidc/callback/apple-a12b-cDe

If you have now configured everything correctly, you will land at Apple, can log in there and will be redirected back to the specified redirect_uri.

Here you will receive a CSRF-Violation error!

According to the documentation, this is probably due to the generated provider ID:
“The provider ID for the web browser flow must be apple. This makes sure that the resulting callback URL will be exempt from CSRF middleware, as Apple uses a POST form request that does not include the CSRF cookie.”

The part of the redirect_uri “apple-a12b-cDe” is also used as the provider ID in the HTML form.

A hard overwrite of the provider ID in the HTML form only triggers a 404 error from Kratos.

Reproducing the bug

  1. Configure Apple as Social Sign In Provider
  2. Test "Sign in with Apple".
  3. Encounter described bug.

Relevant log output

Relevant configuration

Version

Ory Network and Custom UI with @ory/[email protected]

On which operating system are you observing this issue?

Ory Network

In which environment are you deploying?

Ory Network

Additional Context

No response

@vafokroy vafokroy added the bug Something is not working. label Feb 5, 2025
@jonas-jonas
Copy link
Member

Thanks for the report. You can manually change the provider ID to apple via the CLI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something is not working.
Projects
None yet
Development

No branches or pull requests

3 participants