microsoft / Office-Online-Test-Tools-and-Documentation

Office Online test tools and documentation
https://docs.microsoft.com/en-us/microsoft-365/cloud-storage-partner-program/
MIT License
233 stars 161 forks source link

Wopi edition does not load properly after user office online sign-in : access token being cut on redirection #451

Closed mbensoltana closed 2 years ago

mbensoltana commented 2 years ago

As part of the business user flow, users will be asked to sign in using their Office 365 credentials. After sign-in, they will be re-directed to the wopi edition screen. However, the Office Online application fails to load because the authentication cookie joined to the "requestURL" as a query param is being cut by the login flow.

please check the eurl as it's clearly cutting original access token param :

Login interception page link :

https://office.live.com/start/Word.aspx?h4b=Nuxeo&c4b=1&eurl=https%3A%2F%2FMY_CLIENT_HOST%2Eio%2Fnuxeo%2Fwopi%2Fedit%2Fdefault%2F833dd2b2%2Dfac4%2D4a74%2D84ef%2D01ba0d4aefd9%2Ffile%3Acontent&furl=https%3A%2F%2FMY_CLIENT_HOST%2Eio%2Fnuxeo%2Fnxfile%2Fdefault%2F833dd2b2%2Dfac4%2D4a74%2D84ef%2D01ba0d4aefd9%2Ffile%3Acontent%2Ftest%2Edocx%3FchangeToken%3D16%2D3&hp=fILU5%2Bfs3s13x83TSgLuaCX2qSoqrMAOBBwHZFdhwv0%3D

Login link : https://login.windows.net/common/oauth2/authorize?response_mode=form_post&response_type=id_token&scope=openid&msafed=0&nonce=SECRET_NONCE&state=http%3a%2f%2foffice.live.com%2fstart%2fWord.aspx%3fh4b%3dNuxeo%26c4b%3d2%26eurl%3dhttps%253A%252F%252FMY_CLIENT_HOST%252Eio%252Fnuxeo%252Fwopi%252Fedit%252Fdefault%252F833dd2b2%252Dfac4%252D4a74%252D84ef%252D01ba0d4aefd9%252Ffile%253Acontent%26furl%3dhttps%253A%252F%252FMY_CLIENT_HOST%252Eio%252Fnuxeo%252Fnxfile%252Fdefault%252F833dd2b2%252Dfac4%252D4a74%252D84ef%252D01ba0d4aefd9%252Ffile%253Acontent%252Ftest%252Edocx%253FchangeToken%25CHANGE_TOKEN%253D&client_id=CLIENT_ID&redirect_uri=https%3a%2f%2foffice.live.com%2fstart%2fauth%2fsignin

mbensoltana commented 2 years ago

Any news on this guys?

borisf-msft commented 2 years ago

@mbensoltana Thanks for reaching out. We had a brief regression in this flow that should be resolved at this time. If you're still seeing this issue, please let us know via http://aka.ms/cspp-support .

For future issues not related to WOPIValidator, please use the link above which is staffed with Microsoft Support staff.