Client_app_sdk messaging events failing on cross-origin fetch

I might be wrong but I’m seeing a TOTAL failure when trying to trigger a cross-origin fetch from a content script after a client_app_sdk v4.2.1 event. The console is throwing a CORS error even though the headers look right.

In my limited experience, the session token usually holds, but the browser is stripping the auth during the jump. Tried hitting /api/v2/messaging/supportedcontent/{supportedContentId} to verify the connection and it just hangs.

1 Like

The browser blocks the fetch because the origin doesn’t match the SDK context. It’s… a CORS thing with the session. Use the SDK’s internal fetch or the platform’s proxy to keep the token.

// use the sdk client for the call
const response = await clientAppSdk.fetch('/api/v2/conversations/messaging/supportedcontent', {
 method: 'GET'
});

The console just says Access-Control-Allow-Origin missing… not sure why.

2 Likes

client_app_sdk is doing this because of the origin mismatch. That’s right, and also you’ve got to ensure the AllowedOrigins in the OAuth client is set correctly for the custom app domain. Otherwise, the browser won’t let the token pass.

{
 "name": "MyClientApp",
 "grantTypes": ["implicit"],
 "allowedOrigins": ["https://my-custom-app.com"]
}