【问题标题】:Rails / Google SSO - auth popup causing: Blocked a frame with originRails / Google SSO - 身份验证弹出窗口导致:阻止了具有原点的帧
【发布时间】:2015-08-17 16:05:36
【问题描述】:

我有一个使用 Google SSO 登录/注册用户的 Rails 应用。它在 Safari 中运行良好,但在 Chrome 中我不断收到此错误:

Blocked a frame with origin "[domain]" from accessing a frame with origin "https://accounts.google.com". Protocols, domains, and ports must match.

我之前用过这个“解决方案”来解决:https://github.com/zquestz/omniauth-google-oauth2/issues/122#issuecomment-60510241

但我最近注意到它突然停止使用上述解决方案代替 Safari。

我当前的实现如下所示(咖啡脚本):

$(document).ready ->
  $.ajax
    url: 'https://apis.google.com/js/client:plus.js?onload=gpAsyncInit'
    dataType: 'script'
    cache: false

window.gpAsyncInit = ->

  $('.googleplus-login').click (e) ->
  e.preventDefault()

  gapi.auth.authorize {
    immediate: false
    response_type: 'code'
    cookie_policy: 'single_host_origin'
    client_id: '[id]'
    scope: 'email profile'
  }, (response) ->
    if response and !response.error
      # google authentication succeed, now post data to server and handle data  securely
      jQuery.ajax
        type: 'POST'
        url: '/auth/google_oauth2/callback'
        dataType: 'json'
        data: response
        success: (json) ->
          # response from server
          [this doesn't happen]

          return
    else
      # google authentication failed

我没有在 Google 文档的任何地方看到此错误的描述,所以我不太确定如何修复它。

我确定我有相同的协议https,所以它一定是别的东西。我猜是域名。

我看到其他网站(如 Stack-overflow)使用不同的流程,其中不显示弹出窗口,而是将用户重定向到另一个页面。想知道这是否可能是一种解决方案(和/或)推荐的方法来避免我的错误。

在这种情况下,我在 Google 的文档丛林中哪里可以找到这方面的文档?

更新

这是我的控制器代码的相关部分。

def google_authentication

  respond_to do |format|

    code = params[:code]

    unless code.blank?

      [..]

      load = { code: code, client_id: client_id, client_secret: client_secret, grant_type: grant_type, redirect_uri: redirect_uri }
      url = "https://www.googleapis.com/oauth2/v3/token/"
      response = HTTParty.post(url, :query => load, headers: { "content-type" => "application/x-www-form-urlencoded"})
      json = JSON.parse(response.body)

      unless json.nil?

        unless json["error"].present?

          [..]

          email = decoded_hash["email"]
          user = User.find_by_email(email)

          if user
            sign_in_existing_user(user)
            format.json { render :json => {:status => "Success", user_id: "# {user.id}"} }
          else
            # Create user
            [..]
            format.html { redirect_to current_user, notice: "Welcome #{current_user.name}!" }
            format.json { render :json => {:status => "Success", user_id: "#{current_user.id}"} }

          end
        else
          #format.html { redirect_to root_path, error: "Could not sign up / in" }
          format.json { head :no_content }
        end
      end
    end
  end
end

我已经根据@EugZol 下面的回答更新了我的 JS:

data: {access_token: response['access_token'], error: response['error'], expires_in: response['expires_in']}

我目前收到以下错误:

Started POST "/auth/google_oauth2/callback" [..]
Processing by UsersController#google_authentication as JSON
Parameters: {"expires_in"=>"86400", "provider"=>"google_oauth2"}
Completed 406 Not Acceptable in 1ms (ActiveRecord: 0.0ms)

ActionController::UnknownFormat (ActionController::UnknownFormat):
app/controllers/users_controller.rb:237:in `google_authentication'

【问题讨论】:

    标签: javascript ruby-on-rails google-api google-apps google-sso


    【解决方案1】:

    当您尝试向自己的服务器发出请求时,我唯一可以假设的是:

    data: response
    

    ...您的代码正在以间接方式访问由 GAPI 创建的框架。即,response 对象在其框架的内部字段之一中引用,而 jQuery 正在尝试对其进行序列化。

    解决方案是手动选择必填字段:

    data: {
      state: response['state'],
      code: response['code'],
      scope: response['scope'],
      client_id: response['client_id'],
      g_user_cookie_policy: response['g_user_cookie_policy']
    }
    

    【讨论】:

    • 谢谢!当我尝试它时,我收到以下错误:Started POST "/auth/google_oauth2/callback" [...] Processing by UsersController#google_authentication as JSON Parameters: {"expires_in"=>"[exp]", "provider"=>"google_oauth2"} Completed 406 Not Acceptable in 1ms (ActiveRecord: 0.0ms) ActionController::UnknownFormat (ActionController::UnknownFormat): app/controllers/users_controller.rb:237:in google_authentication'。也将使用相关的控制器代码更新我的问题,如果您也可以查看它,将非常感谢!
    • 您似乎还需要传递code 参数。将{code: response['code'], ...} 也添加到Javascript 的data 中。
    • 谢谢!现在它终于奏效了!这是我实际使用的参数(这里不存在访问令牌)data: { state: response['state'], code: response['code'], scope: response['scope'], client_id: response['client_id'], g_user_cookie_policy: response['g_user_cookie_policy'] }
    • 不客气!我编辑了答案以反映实际的哈希键名称。
    猜你喜欢
    • 2015-07-19
    • 1970-01-01
    • 2021-10-25
    • 2020-08-28
    • 1970-01-01
    • 2019-05-15
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多