Wp-calypso: Site Privacy: Users on Private Sites end up in a login loop unable to view site

Created on 23 Nov 2020  路  4Comments  路  Source: Automattic/wp-calypso

Steps to reproduce

  1. As User A, set a site to be private
  2. Invite User B to be a viewer of the site
  3. Attempt to visit site when logged in as User B
  4. Follow prompts to log in for access to Private site

What I expected

After confirming to log in as User B I should see the site content of the Private Site.

What happened instead

I am sent back to the 'Private Site' screen prompting me to login.

Screenshot / Video

Screencast from an actual user:
https://imgur.com/a/keDyjjZ?fbclid=IwAR2lnGBC61oMD3uYjD2ej1WIdJ5NpHZcI-llzXkTMiTpZ4QyFLhPutOMLrA


Shifting this over from this open P2: p2EDhh-1bk-p2

We're seeing an increasing number of reports of this (I'll list them below) and are seeking to get browser information from users who have the problem. I've been able to recreate in Chrome will in a Support Session as a user affected.

Currently, it seems that the problem is caused by a custom domain - switching to using the *.wordpress.com address resolves the issue. It seems that browser cache/cookies clearing has no impact.

PrivacGDPR Subscriptions [Type] Bug

Most helpful comment

Heads up that @Automattic/ganon has been working on related things but they had a look on Monday and concluded that it's not related.

[...] it seems that the problem is caused by a custom domain - switching to using the *.wordpress.com address resolves the issue. It seems that browser cache/cookies clearing has no impact.

cc @daledupreez any changes recently that could impact this?

All 4 comments

Cases so far:

  • #5915641-ch
  • #25114152-hc
  • #3408415-zen
  • #3418338-zen
  • #20100819-hc
  • #3479418-zen
  • #3479418-zen
  • #3512691-zen

Moving to janitorial pri backlog, since we are hitting multiple reports of this happening pretty quickly.

Heads up that @Automattic/ganon has been working on related things but they had a look on Monday and concluded that it's not related.

[...] it seems that the problem is caused by a custom domain - switching to using the *.wordpress.com address resolves the issue. It seems that browser cache/cookies clearing has no impact.

cc @daledupreez any changes recently that could impact this?

Apologies for the delay. AFAIK, we haven't made any direct changes that would affect this.

However, this feels a _lot_ like it could be driven by third party cookie restrictions. cc @josephscott for input on whether that's a likely root cause here.

Was this page helpful?
0 / 5 - 0 ratings