Skip to content

Missing Origin Header #392

Answered by rayluo
ian-cahila-maersk asked this question in Q&A
Discussion options

You must be logged in to vote

(The following content was buried deep down here in the lengthy conversation, and we copied it here for visibility.)

... I can reproduce your "AADSTS9002327: Tokens issued for the 'Single-Page Application' client-type may only be redeemed via cross-origin requests" error, if I deliberately configure my web app as a SPA app (and also skipping its CLIENT_SECRET in my app implementation) - but those were the wrong way to configure/use a web app.

If this was indeed your configuration, I'd suggest you to delete the SPA section, and configure your app as a Web app (or a Desktop app, for that matter). Or you could still have your SPA configuration and your Web/Desktop app configuration co-exist,…

Replies: 2 comments 7 replies

Comment options

You must be logged in to vote
7 replies
@rayluo
Comment options

@ian-cahila-maersk
Comment options

@rayluo
Comment options

@rayluo
Comment options

@ian-cahila-maersk
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by rayluo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants