New issue
Advanced search Search tips

Issue 873306 link

Starred by 1 user

Issue metadata

Status: Unconfirmed
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug



Sign in to add a comment

Cross-Origin Read Blocking (CORB) blocked cross-origin response

Reported by wy345jac...@gmail.com, Aug 10

Issue description

Chrome Version       : Version 68.0.3440.106 (Official Build) (64-bit)
URLs (Only can be access by specific people) :https://uat.cheque-manufacturing.services.dh.com/shell01
Other browsers tested: we only use chrome.
  Add OK or FAIL, along with the version, after other browsers where you
have tested this issue:
     Safari:
    Firefox:
       Edge:

What steps will reproduce the problem?
Only reproduce in my colleague's computer. She can be contacted by email Cheryl.Morrisey@finastra.com or 905 267-5000 x74280
(1)Open chrome browser
(2)input url:https://uat.cheque-manufacturing.services.dh.com/shell01
(3)get the following error message:
Cross-Origin Read Blocking (CORB) blocked cross-origin response https://fs.corp.dh.com/adfs/oauth2/authorize/wia?client_id=794e8798-c776-41b6-b11a-d8ffe500e194&redirect_uri=https%3a%2f%2fuat.cheque-manufacturing.services.dh.com%2fshell01%2f&resource=https%3a%2f%2fuat.cheque-api.services.dh.com%2f&response_mode=form_post&response_type=code+id_token&scope=openid+profile&state=OpenIdConnect.AuthenticationProperties%3d3TvzE2V9604-KYwlwq_GZmET2B00h6zpu7ngTUxVyA8Z27reIGXt5U3qxZz7v4aQ3TKbk5cdvqPPqp96g9bhqUQu1_E31okYyckTlvfteW7_KHFnDBRFpF6CkjZspQ_-5eDcsK337EiMj1Nr9XW2TlSqrMOUjEDzDPW1IoJXPPvULGUUrVMteydPllGS7bTtzEKqZRmyuYzKwdqv8qNOiMt7gVo8oJFYtJ9jYsxn3avNkX8pf_A1TUV6k0HSS6i9bwdpc9HggkMiiPhnDmtLRIqGZUhIEvCOCoaxAP8Vd9QneusFv9_a7AgsHs1o4Pm-CSuVqkR2elNgKb-RqnM6ng&nonce=636694199372196411.Y2UyNTZlY2UtYmY5ZS00NmQxLWI3ZmItYzNmYTdhM2Y1ZTI1NTE0ZGY3M2UtM2I3NC00ZWNlLTlmODktNjNiNzI5OTFhMWNk&client-request-id=7f474745-2a85-4f38-4401-0080010000db with MIME type text/html. See https://www.chromestatus.com/feature/5629709824032768 for more details.

What is the expected result?
Can login successfully

What happens instead?
get the following error message from console output tab page when press F12:
Cross-Origin Read Blocking (CORB) blocked cross-origin response https://fs.corp.dh.com/adfs/oauth2/authorize/wia?client_id=794e8798-c776-41b6-b11a-d8ffe500e194&redirect_uri=https%3a%2f%2fuat.cheque-manufacturing.services.dh.com%2fshell01%2f&resource=https%3a%2f%2fuat.cheque-api.services.dh.com%2f&response_mode=form_post&response_type=code+id_token&scope=openid+profile&state=OpenIdConnect.AuthenticationProperties%3d3TvzE2V9604-KYwlwq_GZmET2B00h6zpu7ngTUxVyA8Z27reIGXt5U3qxZz7v4aQ3TKbk5cdvqPPqp96g9bhqUQu1_E31okYyckTlvfteW7_KHFnDBRFpF6CkjZspQ_-5eDcsK337EiMj1Nr9XW2TlSqrMOUjEDzDPW1IoJXPPvULGUUrVMteydPllGS7bTtzEKqZRmyuYzKwdqv8qNOiMt7gVo8oJFYtJ9jYsxn3avNkX8pf_A1TUV6k0HSS6i9bwdpc9HggkMiiPhnDmtLRIqGZUhIEvCOCoaxAP8Vd9QneusFv9_a7AgsHs1o4Pm-CSuVqkR2elNgKb-RqnM6ng&nonce=636694199372196411.Y2UyNTZlY2UtYmY5ZS00NmQxLWI3ZmItYzNmYTdhM2Y1ZTI1NTE0ZGY3M2UtM2I3NC00ZWNlLTlmODktNjNiNzI5OTFhMWNk&client-request-id=7f474745-2a85-4f38-4401-0080010000db with MIME type text/html. See https://www.chromestatus.com/feature/5629709824032768 for more details.
(index):1 Cross-Origin Read Blocking (CORB) blocked cross-origin response https://fs.corp.dh.com/adfs/oauth2/authorize/wia?client_id=794e8798-c776-41b6-b11a-d8ffe500e194&redirect_uri=https%3a%2f%2fuat.cheque-manufacturing.services.dh.com%2fshell01%2f&resource=https%3a%2f%2fuat.cheque-api.services.dh.com%2f&response_mode=form_post&response_type=code+id_token&scope=openid+profile&state=OpenIdConnect.AuthenticationProperties%3dCcX_p60Ob32Z-mkODf9F1FnKaEEQS_KOzBqGUAGjYHsPWU5ToHClDUm7E8hyyo5rzSERthGSYKzDlHZyDZqPFcEf6m0eK5e3MgO-7CWDga8-Ye1kjrLaM2NsEULBK41FREInWufdbt5rpwDprOoBzFGXEDc1iaPUa0-SFGc6e-V04V_0-vXvUkesBU2G8QlEAsYg2YQj9-2qe7-vd9qHFhivfPCGKB_8PhErFznp9LW3nXzPef78AAaElYLgV0ekyN5vzvi5j3XaL0m-YJGNaNKMRCdkwoEH3neYhuVpwPOf3GNdtWvfEHh0G-ZgDtMcGMbjtjg7DQPkkNEuxa59zA&nonce=636694199372196411.MmNhNWM3MjUtZDIxOC00YmY2LWFiOWMtOGJlZjg4NTA3YmJhNzVjNzliNTctMDRhMS00MTY1LWE1YmUtMjY2NzYxYjQ0ZjNk&client-request-id=3f457037-70d2-4edf-3200-0080000000d4 with MIME type text/html. See https://www.chromestatus.com/feature/5629709824032768 for more details.


Please provide any additional information below. Attach a screenshot if
possible.

 
Navigating to https://uat.cheque-manufacturing.services.dh.com/shell01 results in the following error: DNS_PROBE_FINISHED_NXDOMAIN: uat.cheque-manufacturing.services.dh.com’s server IP address could not be found.  The CORB-blocked resource (https://fs.corp.dh.com/adfs/oauth2/authorize/...) hits a similar problem.

Question: Does the problem persist after disabling CORB by launching Chrome with the following cmdline flags?: --disable-features=CrossSiteDocumentBlockingAlways,CrossSiteDocumentBlockingIfIsolating

Question: Can you please look in the DevTools Network panel to check the http response headers of the blocked response?  This will help verify why the response is blocked.
Question: Does the problem persist after disabling CORB by launching
Chrome with the following cmdline flags?: --disable-features=
CrossSiteDocumentBlockingAlways,CrossSiteDocumentBlockingIfIsolating
The problem disappear after disabling CORB.

Question: Can you please look in the DevTools Network panel to check the
http response headers of the blocked response? This will help verify why
the response is blocked.
I'll let you know next Monday, because my colleague is going off work now.
Do you need the response before I disable CORB or after I disable CORB?

Regards,
Yong Wu
The same http response should be reported in DevTools with and without CORB, so either way should work.  Probably capturing it with CORB enabled makes it easier to double-check that the right response has been captured (by comparing the URL reported in the Network panel and in the CORB error message).
Labels: Needs-Triage-M68
Cc: vamshi.kommuri@chromium.org
Labels: Needs-Feedback Triaged-ET
As per comment#2 adding label Needs-Feedback and requesting reporter to respond back on the info about http response headers of the blocked response in DevTools Network panel i.e., Comment#1(...Comment#3).

Thanks!

Sign in to add a comment