# יצירת חשבון OAuth נכשלת עקב זיהוי CSRF מיד לאחר כניסה ל-Auth0 באותו דפדפן

**URL:** https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112
**Category:** SSO
**Tags:** oauth2
**Created:** [16 בדצמבר,‏ 2022,‏ 10:31am UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112 "2022-12-16T10:31:57Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![joellabes](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/joellabes/32/272968_2.png) [@joellabes](https://meta.discourse.org/u/joellabes)
#### Post date: [16 בדצמבר,‏ 2022,‏ 10:31am UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112/1 "2022-12-16T10:31:58Z")

</div>

We have configured the oauth2 plugin following the directions on [Configure sign up and log in with Auth0 using the OAuth2 Basic Plugin](https://meta.discourse.org/t/configure-sign-up-and-log-in-with-auth0-using-the-oauth2-basic-plugin/64633).

The flow works as follows:

- Users sign up at [https://getdbt.com/community/join-the-community](https://getdbt.com/community/join-the-community)
- They get sent a confirmation email from Auth0
- They land on [https://getdbt.com/community/email-verified](https://getdbt.com/community/email-verified)
- They click _Get help on the community forum_, and are taken to Auth0 to sign in
- After signing in, they are redirected to [discourse.getdbt.com](http://discourse.getdbt.com) but with the CSRF warning displayed.

If they click _Log In_ and then _Use your dbt Community Account_, the **account is successfully created** and they see the account creation dialog where they can set their username etc.

Loom video showing this in action:  
https://www.loom.com/embed/88c95b2cdb074328b380960653469988

I have enabled `oauth2 debug auth` and in the logs can see `(oauth2_basic) Authentication failure! csrf_detected: OmniAuth::Strategies::OAuth2::CallbackError, csrf_detected | CSRF detected`

My questions:

1. Is this a Discourse issue or an Auth0 issue? I assume Discourse since a basically identical login flow for Slack works without issue.
2. Why does this work on the Login page but not when login is triggered from the Auth0 side?
3. The default CSRF error message implies that it happens when the browser changes, or when the login flow takes too long. Neither of those are the case, what else could be causing it?

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [20 בדצמבר,‏ 2022,‏ 10:38am UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112/4 "2022-12-20T10:38:11Z")

</div>

Hi @joellabes - please can you check what URL you’ve entered in the “Application Login URI” Auth0 setting?

 ![Screenshot 2022-12-20 at 10.35.50](https://global.discourse-cdn.com/meta/original/4X/6/7/d/67d1f894491587f393b96989820a63bd9f306491.png)

It should be `{your forum}/auth/oauth2_basic`. If you have `/callback` on the end, that could cause the issue you described.

---

<div class="post-metadata">

### Author: ![joellabes](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/joellabes/32/272968_2.png) [@joellabes](https://meta.discourse.org/u/joellabes)
#### Post date: [20 בדצמבר,‏ 2022,‏ 6:13pm UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112/5 "2022-12-20T18:13:53Z")

</div>

Thanks @david - right now I don’t have anything in the Application Login URI box, but do have something in allowed callback URLs:

 ![image](https://global.discourse-cdn.com/meta/original/4X/c/9/d/c9dcfd832d873bf26528cd3f0acb7ae0f4cd92ed.png)

Should I put `https://discourse.getdbt.com/auth/oauth2_basic` in the Application Login URI field and leave `https://discourse.getdbt.com/auth/oauth2_basic/callback` in the Allowed Callback URLs field?

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [20 בדצמבר,‏ 2022,‏ 6:33pm UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112/6 "2022-12-20T18:33:29Z")

</div>

You could try that, yes.

Can you share some more detail about how the “Get help on the Community Forum” link is implemented? Where does the link go? I am currently assuming that the button is handled by Auth0, and that adding that new URL configuration will cause the button to correctly link to `/auth/oauth2_basic` to start the login flow.

---

<div class="post-metadata">

### Author: ![joellabes](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/joellabes/32/272968_2.png) [@joellabes](https://meta.discourse.org/u/joellabes)
#### Post date: [13 בינואר,‏ 2023,‏ 2:51am UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112/7 "2023-01-13T02:51:09Z")

</div>

Sorry for the slow reply - just getting back after the Christmas break!

I did this:

> [@joellabes](#):
>
> Should I put `https://discourse.getdbt.com/auth/oauth2_basic` in the Application Login URI field and leave `https://discourse.getdbt.com/auth/oauth2_basic/callback` in the Allowed Callback URLs field?

but still get the same result.

> [@david](#):
>
> Where does the link go?

That link points to `https://dev-zb38hsho.us.auth0.com/samlp/5GpVvVgryMnBaNJFuLt5DW3bs89jO0hr`, where `dev-zb38hsho` is our Auth0 instance ID and `5GpVvVgryMnBaNJFuLt5DW3bs89jO0hr` is the Client ID for the Discourse Application in Auth0.

Visiting that link redirects to `https://dev-zb38hsho.us.auth0.com/u/login?state=SESSION_SPECIFIC_TOKEN`.

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [13 בינואר,‏ 2023,‏ 9:42am UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112/8 "2023-01-13T09:42:01Z")

</div>

The key is that Discourse needs to start the authentication flow at `/auth/oauth2_basic`, then redirect to Auth0, then come back to `/auth/oauth2_basic/callback`.

I was hoping we could get Auth0 to trigger login by starting with the first URL, but it sounds like it’s jumping Discourse straight to the callback URL.

Could you update the button to point to `/auth/oauth2_basic` on the forum? That will start the authentication flow and immediately redirect to Auth0, so the overall UX should be the same.

---

<div class="post-metadata">

### Author: ![joellabes](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/joellabes/32/272968_2.png) [@joellabes](https://meta.discourse.org/u/joellabes)
#### Post date: [17 בינואר,‏ 2023,‏ 3:38am UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112/9 "2023-01-17T03:38:49Z")

</div>

Yes that works! It does pause on an interstitial page with a Continue button; is user interaction mandatory to safely trigger an OAuth flow or something?

 ![image](https://global.discourse-cdn.com/meta/original/4X/f/4/d/f4d4080c1d0e8b4ad58356b5d37711f26a606cd8.png)

If there’s a way to make it

> [@david](#):
>
> immediately redirect to Auth0

then that would be a bonus but this is great! Thank you 🙏

---

<div class="post-metadata">

### Author: ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)
#### Post date: [17 בינואר,‏ 2023,‏ 9:41am UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112/10 "2023-01-17T09:41:39Z")

</div>

That page is shown when there are multiple login methods on a site. If you disable ‘local logins’ (username/password) then it should go straight through to the login process.

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [16 בפברואר,‏ 2023,‏ 9:41am UTC](https://meta.discourse.org/t/oauth-account-creation-fails-due-to-csrf-detection-immediately-after-logging-into-auth0-on-same-browser/249112/11 "2023-02-16T09:41:42Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
