I’ve been using Auth0 with a SPA and Vue2 for years on my dev PC. From last week, I have been getting the Authorization App screen for my account on every page refresh. I did not touch any config or update any package.
Is there a new config in Auth0 that has been updated? This happens on localhost only. There is no problem in the online version.
Thank you.
Hi @evographics,
Welcome back to the Auth0 Community!
The reason why you are encountering this issue only on localhost is because localhost cannot be verified as a first-party application, as any malicious application could run on it. This is not recent change and it is explained under our User Consent and Third-Party Applications documentation.
I hope this helps! If you have any other question please let me know.
Best regards,
Remus
@remus.ivan Thank you so much for your feedback. We never experienced this issue before. It began last week.
Is there a solution for preventing it during our development?
Many thanks
Your Auth0 SPA with Vue2 is showing the Authorization App screen on every page refresh on localhost, even though you made no configuration changes and the production version works fine.
A new Auth0 security feature now requires user confirmation when an application redirects to a non-verifiable callback address like localhost. This is causing the repeated authorization prompts on every page refresh.
[Root Cause]
Auth0 recently introduced a new security feature called Non-Verifiable Callback URI End-User Confirmation. This feature requires users to confirm authorization when an application redirects to a non-verifiable callback address (such as localhost). This is a security measure to prevent malicious applications from redirecting to unverifiable addresses.
Since localhost cannot be verified as a legitimate domain, Auth0 now prompts for confirmation on every redirect, which is why you see the Authorization App screen on every page refresh.
[Solution]
To disable this confirmation requirement for local development, turn off the Non-Verifiable Callback URI End-User Confirmation setting:
Option 1: Disable for Your Application Only (Recommended for Development)
- Navigate to Auth0 Dashboard → Applications → Your Application
- Click Settings
- Scroll to Advanced settings
- Find Non-Verifiable Callback URI End-User Confirmation
- Toggle off the setting
- Click Save
Option 2: Disable for Your Entire Tenant
- Navigate to Auth0 Dashboard → Settings
- Click Advanced
- Find Non-Verifiable Callback URI End-User Confirmation
- Toggle off the setting
- Click Save
After disabling this setting, page refreshes on localhost will no longer trigger the Authorization App screen.
You can read more about this here:
This resolves the issue and allows you to continue developing locally without repeated authorization prompts.
Best Regards,
Remus