#1107300 firefox-esr: tracking protection fails to retrieve json cookie at login resulting in an incorrect cross-origin block

Package:
firefox-esr
Source:
firefox-esr
Description:
Mozilla Firefox web browser - Extended Support Release (ESR)
Submitter:
Scott MacKenzie
Date:
2025-06-05 03:33:02 UTC
Severity:
normal
Tags:
#1107300#5
Date:
2025-06-05 03:30:30 UTC
From:
To:
Dear Maintainer,

Firefox ETP attempts to check a site-login cookie (intra-site, not cross-site not advertising-related AFAIK), retrieved from Cisco subsidiary, App Dynamics adtrum.js, but fails and (from console-tab) results in a...

Cross-Origin Request Blocked: The Same Origin Policy disallows reading the remote resource at https://thirdparty-request.bankingsite.com/oauth/token. (Reason: CORS header ‘Access-Control-Allow-Origin’ missing). Status code: 403

Also (network-tab) has two requests, what I believe to be the original genuine request generated by 'adtrum.js' which is text/plain and succeeds, followed by what I suspect is an ETP request text/html which fails with a '403 Forbidden' response.

Reference may assist https://docs.appdynamics.com/appd/23.x/23.11/en/end-user-monitoring/browser-monitoring/browser-real-user-monitoring/troubleshoot-browser-rum/javascript-errors?scroll-versions:version-name=23.12

I looked at #814188 but thought it to be different if similar.

If this has been fixed upstream, then consider this a request for a stable-backport inclusion.

I use private-browsing mode for this website. The ETP exception list is not consulted in private-browsing mode.  I can work-around the issue by disabling the ETP padlock and waiting for a typical 10-minute period before reloading the page with a normal 'ctrl-R' (ctrl-shift-R doesn't appear to help), I can then login successfully but have to repeat this every time that firefox is restarted due to there being no permanent exception.

I won't provide logs unless I can anonymize all the domain-related information.


Regards,

Scott.