Skip to content

Sign in BBCiD broken: BBC has moved account.bbc.com to a React/ AWS-WAF sign-in flow; SignInBBCiD() scraping no longer works #413

Description

@angusdunnett

"Sign in BBCiD" fails: the addon displays the error message "NoneType object is not subscriptable" when attempting to sign in.

Cause

SignInBBCiD() in resources/lib/ipwww_common.py (around lines 238–287) signs in by scraping the BBC account sign-in page HTML: it loads account.bbc.com and extracts the form with a regex such as action="([^"]*)", then posts credentials.

The BBC has replaced that server-rendered sign-in page with a React application behind AWS WAF:

  • The sign-in form and its action URL are no longer present in the initial HTML, so the action="..." regex matches nothing and sign-in aborts.
  • The page loads challenge.js, which sets an aws-waf-token cookie; requests without a valid token are challenged. (The config meta tag shows wafSDK: "soft-block", but the token is still required for the sign-in POST path.)
  • The sign-in flow is now a redirect chain: account.bbc.com/signin/identity?policy=...&ptrt=<return-url>, driven by client-side JavaScript, with API calls built at runtime from the config's backendGatewayBaseUrl (https://account-backend-gateway.api.bbci.co.uk/v3). Static scraping of the page cannot reconstruct this.

To reproduce

  1. Fresh install of the add-on (or delete the stored cookie jar).
  2. Enter bbc credentials in addon settings
  3. Click on "Continue Watching" or other item which requires signing in

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions