"Sign in BBCiD" fails: the addon displays the error message "NoneType object is not subscriptable" when attempting to sign in.
Cause
SignInBBCiD() in resources/lib/ipwww_common.py (around lines 238–287) signs in by scraping the BBC account sign-in page HTML: it loads account.bbc.com and extracts the form with a regex such as action="([^"]*)", then posts credentials.
The BBC has replaced that server-rendered sign-in page with a React application behind AWS WAF:
- The sign-in form and its
action URL are no longer present in the initial HTML, so the action="..." regex matches nothing and sign-in aborts.
- The page loads
challenge.js, which sets an aws-waf-token cookie; requests without a valid token are challenged. (The config meta tag shows wafSDK: "soft-block", but the token is still required for the sign-in POST path.)
- The sign-in flow is now a redirect chain:
account.bbc.com/signin/identity?policy=...&ptrt=<return-url>, driven by client-side JavaScript, with API calls built at runtime from the config's backendGatewayBaseUrl (https://account-backend-gateway.api.bbci.co.uk/v3). Static scraping of the page cannot reconstruct this.
To reproduce
- Fresh install of the add-on (or delete the stored cookie jar).
- Enter bbc credentials in addon settings
- Click on "Continue Watching" or other item which requires signing in
"Sign in BBCiD" fails: the addon displays the error message "NoneType object is not subscriptable" when attempting to sign in.
Cause
SignInBBCiD()inresources/lib/ipwww_common.py(around lines 238–287) signs in by scraping the BBC account sign-in page HTML: it loadsaccount.bbc.comand extracts the form with a regex such asaction="([^"]*)", then posts credentials.The BBC has replaced that server-rendered sign-in page with a React application behind AWS WAF:
actionURL are no longer present in the initial HTML, so theaction="..."regex matches nothing and sign-in aborts.challenge.js, which sets anaws-waf-tokencookie; requests without a valid token are challenged. (The config meta tag showswafSDK: "soft-block", but the token is still required for the sign-in POST path.)account.bbc.com/signin/identity?policy=...&ptrt=<return-url>, driven by client-side JavaScript, with API calls built at runtime from the config'sbackendGatewayBaseUrl(https://account-backend-gateway.api.bbci.co.uk/v3). Static scraping of the page cannot reconstruct this.To reproduce