metamask-mobile icon indicating copy to clipboard operation
metamask-mobile copied to clipboard

CSRF token is not accepted on metamask mobile app browser

Open uraxlizard opened this issue 3 years ago • 1 comments

Description Ajax post request is returning 'Page Expired' when you try to use metmask mobile app browser on Android. On iOS is working. A registration/login flow was created with web3 auth. It was used csrf in order to protect requests, but metmask browser is not accepting them.

To Reproduce Try to make post request with csrf(cors). Bare in mind that this problem occurs only on android devices.

Expected behavior It is expected to be able to capture CSRF and complete the request as expected.

Smartphone:

  • Device: Samsung Galaxy S22 Ultra
  • OS: Android 12
  • App Version v5.6.1(967)

to be added after bug submission by internal support / PM Severity

  • This is a major critical bug as, metamask auth can not be integrated for android users via web3

uraxlizard avatar Sep 21 '22 12:09 uraxlizard

Probably related to https://github.com/MetaMask/metamask-mobile/issues/4979

tommasini avatar Sep 21 '22 17:09 tommasini

Thanks for reporting @uraxlizard! can you try to reproduce on v5.8 or v5.9?

cortisiko avatar Oct 26 '22 17:10 cortisiko

@omnat need product review. See @sethkfman for details.

chrisleewilcox avatar Nov 08 '22 18:11 chrisleewilcox

This issue has been automatically marked as stale because it has not had recent activity in the last 90 days. It will be closed in 7 days. Thank you for your contributions.

github-actions[bot] avatar May 23 '23 17:05 github-actions[bot]

This issue was closed because it has been stalled for 7 days with no activity. If you feel this was closed in error please reopen and provide evidence on the current production app. Thank you for your contributions.

github-actions[bot] avatar Jun 04 '23 16:06 github-actions[bot]