Skip to content
Draft
Changes from 7 commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
e1a71fb
Initial plan for issue
Copilot May 20, 2025
d1ffffc
Fix Safari SecurityError when Block All Cookies is set
Copilot May 20, 2025
c13a592
Fix PR comments on StorageHelperFuncs.ts
Copilot May 20, 2025
16f3b92
Remove newline changes from interface files per PR feedback
Copilot May 21, 2025
a488d75
Refactor storage helper functions to use single return statements per…
Copilot May 21, 2025
fd68d94
Remove generated JS files from PR per feedback
Copilot May 21, 2025
831c9b4
Remove RequestResponseHeaders.ts from PR per reviewer feedback
Copilot May 21, 2025
d472d65
Pass resolved string to _canSafelyAccessStorage per PR feedback
Copilot May 21, 2025
d2cd04d
Merge _canSafelyAccessStorage function into _getVerifiedStorageObject
Copilot May 21, 2025
93c0f44
Simplify storage access code with default-false approach
Copilot May 22, 2025
d4677e0
Merge branch 'main' into copilot/fix-2494
MSNev May 22, 2025
cdf088a
Remove unnecessary nested try-catch for direct storage access
Copilot May 22, 2025
22169a2
Merge branch 'main' into copilot/fix-2494
MSNev May 23, 2025
cee30cd
Add caching to storage verification to reduce test item creation
Copilot May 23, 2025
9e5c985
Update storage caching to use createCachedValue instead of reset
Copilot May 23, 2025
d0ee829
Remove _canUseLocalStorage and _canUseSessionStorage flags, add stora…
Copilot May 23, 2025
2274771
Don't reset cached storage on getItem and read operations
Copilot May 24, 2025
59362d4
Simplify storage wrapper and remove redundant code
Copilot May 24, 2025
b9789af
Use existing helper functions in utlCanUseLocalStorage/SessionStorage
Copilot May 24, 2025
e775471
Refactor storage helper functions to reduce code duplication and fix …
Copilot May 24, 2025
d25a325
Merge branch 'main' into copilot/fix-2494
MSNev May 27, 2025
7e32aa3
Address PR comments for StorageHelperFuncs.ts
Copilot May 27, 2025
ec81543
Refactor storage functions per PR feedback
Copilot May 28, 2025
23f5e50
Refactor utlCanUseLocalStorage and utlCanUseSessionStorage to include…
Copilot May 28, 2025
98c0e2c
Revert utility functions to original form while keeping _throwInterna…
Copilot May 28, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
84 changes: 71 additions & 13 deletions shared/AppInsightsCommon/src/StorageHelperFuncs.ts
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ import {
IDiagnosticLogger, _eInternalMessageId, _throwInternal, dumpObj, eLoggingSeverity, getExceptionName, getGlobal, getGlobalInst,
isNullOrUndefined, objForEachKey
} from "@microsoft/applicationinsights-core-js";
import { objGetOwnPropertyDescriptor } from "@nevware21/ts-utils";
import { StorageType } from "./Enums";

let _canUseLocalStorage: boolean = undefined;
Expand All @@ -23,31 +24,88 @@ function _getLocalStorageObject(): Storage {
return null;
}

/**
* Safely checks if storage object (localStorage or sessionStorage) is available and accessible
* This helps prevent SecurityError in some browsers (e.g., Safari) when cookies are blocked
* @param storageType - Type of storage
* @returns {boolean} Returns whether storage object is safely accessible
*/
function _canSafelyAccessStorage(storageType: StorageType): boolean {
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lets merge this function into the called as it should create smaller code

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've merged the _canSafelyAccessStorage function into _getVerifiedStorageObject as requested, which should create smaller and more efficient code. All safety checks for handling Safari with blocked cookies are preserved in the integrated implementation. d2cd04d

const storageTypeName = storageType === StorageType.LocalStorage ? "localStorage" : "sessionStorage";
let result = true;

try {
// First, check if window exists and get the global object once
const gbl: any = getGlobal();
Comment thread
MSNev marked this conversation as resolved.
Outdated
if (isNullOrUndefined(gbl)) {
result = false;
} else {
// Try to indirectly check if the property exists and is accessible
// This avoids direct property access that might throw in Safari with "Block All Cookies" enabled

// Some browsers throw when accessing the property descriptors with getOwnPropertyDescriptor
// Others throw when directly accessing the storage objects
// This approach tries both methods safely
try {
// Method 1: Try using property descriptor - safer in Safari with cookies blocked
const descriptor = objGetOwnPropertyDescriptor(gbl, storageTypeName);
if (!descriptor || !descriptor.get) {
result = false;
}
} catch (e) {
// If the above fails, attempt a direct access inside a try-catch
try {
const storage = gbl[storageTypeName];
if (!storage) {
result = false;
}
} catch (e) {
// If both approaches fail, storage cannot be safely accessed
result = false;
}
}
}
} catch (e) {
result = false;
}

return result;
}

/**
* Tests storage object (localStorage or sessionStorage) to verify that it is usable
* More details here: https://mathiasbynens.be/notes/localstorage-pattern
* @param storageType - Type of storage
* @returns {Storage} Returns storage object verified that it is usable
*/
function _getVerifiedStorageObject(storageType: StorageType): Storage {
let result = null;

try {
if (isNullOrUndefined(getGlobal())) {
return null;
}
let uid = (new Date).toString();
let storage: Storage = getGlobalInst(storageType === StorageType.LocalStorage ? "localStorage" : "sessionStorage");
let name:string = _storagePrefix + uid;
storage.setItem(name, uid);
let fail = storage.getItem(name) !== uid;
storage.removeItem(name);
if (!fail) {
return storage;
// First check if we can safely access the storage object
if (_canSafelyAccessStorage(storageType)) {
const storageTypeName = storageType === StorageType.LocalStorage ? "localStorage" : "sessionStorage";
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pass the resolved string into the _canSafelyAccessStorage to avoid the duplication of the strings

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've refactored the code to pass the resolved storage type string to the _canSafelyAccessStorage function, eliminating the duplication of string resolution. The storage type name is now determined once in the _getVerifiedStorageObject function and passed to _canSafelyAccessStorage. d472d65


// Now we can safely try to use the storage
try {
let uid = (new Date).toString();
let storage: Storage = getGlobalInst(storageTypeName);
let name:string = _storagePrefix + uid;
storage.setItem(name, uid);
let fail = storage.getItem(name) !== uid;
storage.removeItem(name);
if (!fail) {
result = storage;
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Change this to return a wrapped version of the storage obejct which wraps the setItem() function in a try / catch that handles the failure and resets the state (by setting the value to null)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added a storage wrapper in d0ee829 that wraps all Storage operations in try/catch blocks. All storage methods now reset the cached storage state if they encounter an error.

}
} catch (exception) {
// Storage exists but can't be used (quota exceeded, etc.)
}
}
} catch (exception) {
// eslint-disable-next-line no-empty
// Catch any unexpected errors
}

return null;
return result;
}

/**
Expand Down