SAP Knowledge Base Article - Preview

3781738 - Intermittent 403 "Invalid CORS request" on /authorizationserver/csrf with Custom Login Page when the authorization flow runs through the storefront domain

Symptom

After upgrading SAP Commerce Cloud to JDK21 and adopting the new OAuth implementation with a Custom Login Page, users intermittently receive an HTTP 403 response with the plain text body "Invalid CORS request" when the storefront calls the /authorizationserver/csrf endpoint. The same request succeeds with HTTP 200 on some attempts and fails with HTTP 403 on others, with no apparent pattern from the user's perspective. The failure is not tied to login credentials and does not require a session timeout to occur. When it happens during the login flow, the user cannot obtain a valid CSRF token, cannot complete authentication, and is blocked from proceeding to checkout.

The behavior appears random when observed from the browser. Refreshing the CSRF endpoint repeatedly returns an alternating mix of 200 and 403 responses. On environments running a single API pod the issue does not surface, while on environments running more than one API pod it appears frequently.


Read more...

Environment

SAP Commerce Cloud

Product

SAP Commerce Cloud all versions

Keywords

SAP Commerce Cloud, authorizationserver, csrf, Invalid CORS request, 403 Forbidden, JDK21, OAuth, Composable Storefront, JS Storefront, Spartacus, Custom Login Page page, AuthConfig, baseUrl, publicSpaUri, occ backend base url, JSESSIONID, ROUTE cookie, sticky session, session affinity, load balancer, API node, API pod, API, authorization code flow, custom domain, same domain, subdomain, login, checkout , KBA , CEC-SCC-PLA-PL , Platform , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.