Open Bug 1944606 Opened 9 months ago Updated 4 months ago

office 365 repeatedly prompts for access to shared doc

Categories

(Web Compatibility :: Privacy: Site Reports, defect, P3)

Tracking

(Not tracked)

People

(Reporter: edgul, Unassigned)

References

(Blocks 1 open bug, )

Details

McMaster University's office 365 documents request access every time the user "loads the page", despite that access had already been granted previously.
I'm not sure if this is only happening per session or on every single reload.
I'm currently not sure if they had their settings set to clear data on close, but probably not.
Reporting for a friend.

The warning reads:
Allow access to Microsoft 365 account. Your browser settings are preventing an optimal experience with Microsoft 365. Allow access to improve your experience + <allow access button>

Disabling ETP seems to fix the issue.
Adding the following URLs to ETP exceptions also gets rid of the warning:
https://mcmasteru365-my.sharepoint.com
https://mcmasteru365.sharepoint.com

I was not able to reproduce with my own personal shared doc.

I wonder if this could be dFPI related breakage. For that adding the sharepoint domain for the shim here could help: https://searchfox.org/mozilla-central/rev/f9f9b422f685244dcd3f6826b70d34a496ce5853/browser/extensions/webcompat/data/shims.js#716
The problem is we don't have a way to reproduce this ourselves. It also works fine for me using a non enterprise MS account.

I'm also curious what the "Allow access to improve your experience" button does. Could that be an interstitial for a Storage Access API call?

I can reproduce with a Microsoft enterprise login. I'll experiment with the shim.

Severity: -- → S3
Priority: -- → P2

Found a support thread where users talk about this issue.

Assignee: nobody → emz
Status: NEW → ASSIGNED

I've reached out to folks at Microsoft to learn more about this warning and see if it's fixable on their end.

Couldn't find a straightforward way to shim this (it may still be possible). I'm hoping that Microsoft can fix this. The prompt is annoying but it's not blocking access to the app.

Assignee: emz → nobody
Status: ASSIGNED → NEW
Priority: P2 → P3
Component: Privacy: Anti-Tracking → Privacy: Site Reports
Product: Core → Web Compatibility
You need to log in before you can comment on or make changes to this bug.