<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Open Application from Portal without another login in ArcGIS JavaScript Maps SDK Questions</title>
    <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/open-application-from-portal-without-another-login/m-p/596249#M55892</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a Portal site setup and a custom application configured as a shared application&amp;nbsp;in portal. &amp;nbsp;When the user clicks on the application it redirects the user to the application and then the application redirects the user to portal to login. &amp;nbsp;If the user logs in again everything works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to avoid making the user log back in though since they just logged into portal. &amp;nbsp;I've actually made this all work by reading the esri_auth cookie, but this requires that the custom application be hosted on the portal machine, which I can't really force on clients. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One possible solution that I was not able to complete was to find a way to make the esri_auth cookie's Domain NOT include the machine name and simply be a .domain.com instead of portal.domain.com. &amp;nbsp;I feel like this should be possible since if you look at the esri_auth token provided by arcgisonline you will see that it is just .arcgis.com instead of map.company.arcgis.com. &amp;nbsp;If I can get this to work I have no problems with telling a client that portal and the application need to be on the same domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I feel like that is a bit hacky and should not be necessarily. &amp;nbsp;Am I missing something with the redirect to enable it to pick up the fact that the user had already logged in? &amp;nbsp;The call to /portal/sharing/rest/oauth2/authorize?response_type=code&amp;amp;client_id=..&amp;amp;redirect_url=.. has the esri_auth cookie, so it should know that the user is already authenticated. &amp;nbsp;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be a appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff Machamer&lt;/P&gt;&lt;P&gt;3-GIS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Apr 2017 19:06:15 GMT</pubDate>
    <dc:creator>JeffMachamer</dc:creator>
    <dc:date>2017-04-04T19:06:15Z</dc:date>
    <item>
      <title>Open Application from Portal without another login</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/open-application-from-portal-without-another-login/m-p/596249#M55892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a Portal site setup and a custom application configured as a shared application&amp;nbsp;in portal. &amp;nbsp;When the user clicks on the application it redirects the user to the application and then the application redirects the user to portal to login. &amp;nbsp;If the user logs in again everything works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to avoid making the user log back in though since they just logged into portal. &amp;nbsp;I've actually made this all work by reading the esri_auth cookie, but this requires that the custom application be hosted on the portal machine, which I can't really force on clients. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One possible solution that I was not able to complete was to find a way to make the esri_auth cookie's Domain NOT include the machine name and simply be a .domain.com instead of portal.domain.com. &amp;nbsp;I feel like this should be possible since if you look at the esri_auth token provided by arcgisonline you will see that it is just .arcgis.com instead of map.company.arcgis.com. &amp;nbsp;If I can get this to work I have no problems with telling a client that portal and the application need to be on the same domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I feel like that is a bit hacky and should not be necessarily. &amp;nbsp;Am I missing something with the redirect to enable it to pick up the fact that the user had already logged in? &amp;nbsp;The call to /portal/sharing/rest/oauth2/authorize?response_type=code&amp;amp;client_id=..&amp;amp;redirect_url=.. has the esri_auth cookie, so it should know that the user is already authenticated. &amp;nbsp;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be a appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff Machamer&lt;/P&gt;&lt;P&gt;3-GIS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Apr 2017 19:06:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/open-application-from-portal-without-another-login/m-p/596249#M55892</guid>
      <dc:creator>JeffMachamer</dc:creator>
      <dc:date>2017-04-04T19:06:15Z</dc:date>
    </item>
  </channel>
</rss>

