Bug 1740329 Comment 1 Edit History

Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.

Specifically we're seeing this on our Common CA Database app at https://ccadb.my.salesforce.com/, which appears to involve resources from *.salesforce.com and  *.visualforce.com (and maybe *.force.com, too?). The initial login works fine, but after several hours (maybe when an oauth token needs to be refreshed?) we get the above message.

I don't know if Salesforce could fix this on their end by using the Storage Access API, or if we need a compat-shim of some kind for safeforce apps. Can't really call it a "bug" in dFPI -- this is just a natural consequence. There are few enough users of CCADB that we could just instruct them all to turn off dFPI or add cookie exceptions for the domains involved, but I'm pretty confident all the ".my.safeforce.com" apps (and maybe more salesforce things) are going to have this issue. That's a whole ton of users judging by their revenue numbers
Specifically we're seeing this on our Common CA Database app at https://ccadb.my.salesforce.com/, which appears to involve resources from *.salesforce.com and  *.visualforce.com (and maybe *.force.com, too?). The initial login works fine, but after several hours (maybe when an oauth token needs to be refreshed?) we get the above message.

I don't know if Salesforce will fix this on their end by using the Storage Access API, or if we need a compat-shim of some kind for safeforce apps. Can't really call it a "bug" in dFPI -- this is just a natural consequence. There are few enough users of CCADB that we could just instruct them all to turn off dFPI or add cookie exceptions for the domains involved, but I'm pretty confident all the ".my.safeforce.com" apps (and maybe more salesforce things) are going to have this issue. That's a whole ton of users judging by their revenue numbers

Back to Bug 1740329 Comment 1