I might be wrong but I’m seeing a TOTAL failure when trying to trigger a cross-origin fetch from a content script after a client_app_sdkv4.2.1 event. The console is throwing a CORS error even though the headers look right.
In my limited experience, the session token usually holds, but the browser is stripping the auth during the jump. Tried hitting /api/v2/messaging/supportedcontent/{supportedContentId} to verify the connection and it just hangs.
The browser blocks the fetch because the origin doesn’t match the SDK context. It’s… a CORS thing with the session. Use the SDK’s internal fetch or the platform’s proxy to keep the token.
// use the sdk client for the call
const response = await clientAppSdk.fetch('/api/v2/conversations/messaging/supportedcontent', {
method: 'GET'
});
The console just says Access-Control-Allow-Origin missing… not sure why.
client_app_sdk is doing this because of the origin mismatch. That’s right, and also you’ve got to ensure the AllowedOrigins in the OAuth client is set correctly for the custom app domain. Otherwise, the browser won’t let the token pass.