-
Notifications
You must be signed in to change notification settings - Fork 257
Fix Safari SecurityError when Block All Cookies is enabled #2539
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from 4 commits
e1a71fb
d1ffffc
c13a592
16f3b92
a488d75
fd68d94
831c9b4
d472d65
d2cd04d
93c0f44
d4677e0
cdf088a
22169a2
cee30cd
9e5c985
d0ee829
2274771
59362d4
b9789af
e775471
d25a325
7e32aa3
ec81543
23f5e50
98c0e2c
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -5,6 +5,7 @@ import { | |
| IDiagnosticLogger, _eInternalMessageId, _throwInternal, dumpObj, eLoggingSeverity, getExceptionName, getGlobal, getGlobalInst, | ||
| isNullOrUndefined, objForEachKey | ||
| } from "@microsoft/applicationinsights-core-js"; | ||
| import { objGetOwnPropertyDescriptor } from "@nevware21/ts-utils"; | ||
| import { StorageType } from "./Enums"; | ||
|
|
||
| let _canUseLocalStorage: boolean = undefined; | ||
|
|
@@ -23,6 +24,53 @@ function _getLocalStorageObject(): Storage { | |
| return null; | ||
| } | ||
|
|
||
| /** | ||
| * Safely checks if storage object (localStorage or sessionStorage) is available and accessible | ||
| * This helps prevent SecurityError in some browsers (e.g., Safari) when cookies are blocked | ||
| * @param storageType - Type of storage | ||
| * @returns {boolean} Returns whether storage object is safely accessible | ||
| */ | ||
| function _canSafelyAccessStorage(storageType: StorageType): boolean { | ||
|
||
| const storageTypeName = storageType === StorageType.LocalStorage ? "localStorage" : "sessionStorage"; | ||
|
|
||
| try { | ||
| // First, check if window exists and get the global object once | ||
| const gbl: any = getGlobal(); | ||
| if (isNullOrUndefined(gbl)) { | ||
| return false; | ||
|
||
| } | ||
|
|
||
| // Try to indirectly check if the property exists and is accessible | ||
| // This avoids direct property access that might throw in Safari with "Block All Cookies" enabled | ||
|
|
||
| // Some browsers throw when accessing the property descriptors with getOwnPropertyDescriptor | ||
| // Others throw when directly accessing the storage objects | ||
| // This approach tries both methods safely | ||
| try { | ||
| // Method 1: Try using property descriptor - safer in Safari with cookies blocked | ||
| const descriptor = objGetOwnPropertyDescriptor(gbl, storageTypeName); | ||
| if (!descriptor || !descriptor.get) { | ||
| return false; | ||
| } | ||
| } catch (e) { | ||
| // If the above fails, attempt a direct access inside a try-catch | ||
| try { | ||
| const storage = gbl[storageTypeName]; | ||
| if (!storage) { | ||
| return false; | ||
| } | ||
| } catch (e) { | ||
| // If both approaches fail, storage cannot be safely accessed | ||
| return false; | ||
| } | ||
| } | ||
|
|
||
| return true; | ||
| } catch (e) { | ||
| return false; | ||
| } | ||
| } | ||
|
|
||
| /** | ||
| * Tests storage object (localStorage or sessionStorage) to verify that it is usable | ||
| * More details here: https://mathiasbynens.be/notes/localstorage-pattern | ||
|
|
@@ -31,20 +79,30 @@ function _getLocalStorageObject(): Storage { | |
| */ | ||
| function _getVerifiedStorageObject(storageType: StorageType): Storage { | ||
| try { | ||
| if (isNullOrUndefined(getGlobal())) { | ||
| // First check if we can safely access the storage object | ||
| if (!_canSafelyAccessStorage(storageType)) { | ||
|
||
| return null; | ||
| } | ||
| let uid = (new Date).toString(); | ||
| let storage: Storage = getGlobalInst(storageType === StorageType.LocalStorage ? "localStorage" : "sessionStorage"); | ||
| let name:string = _storagePrefix + uid; | ||
| storage.setItem(name, uid); | ||
| let fail = storage.getItem(name) !== uid; | ||
| storage.removeItem(name); | ||
| if (!fail) { | ||
| return storage; | ||
|
|
||
| const storageTypeName = storageType === StorageType.LocalStorage ? "localStorage" : "sessionStorage"; | ||
|
|
||
| // Now we can safely try to use the storage | ||
| try { | ||
| let uid = (new Date).toString(); | ||
| let storage: Storage = getGlobalInst(storageTypeName); | ||
| let name:string = _storagePrefix + uid; | ||
| storage.setItem(name, uid); | ||
| let fail = storage.getItem(name) !== uid; | ||
| storage.removeItem(name); | ||
| if (!fail) { | ||
| return storage; | ||
| } | ||
| } catch (exception) { | ||
| // Storage exists but can't be used (quota exceeded, etc.) | ||
| return null; | ||
| } | ||
| } catch (exception) { | ||
| // eslint-disable-next-line no-empty | ||
| // Catch any unexpected errors | ||
| } | ||
|
|
||
| return null; | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
reemove this file from the PR
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I've removed RequestResponseHeaders.ts from the PR in commit a488d75.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
remove again
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The RequestResponseHeaders.ts file has been removed from the PR in commit 831c9b4.