Why we can click login button multiple times

Kazuki.Sato 1 Reputation point
2021-08-06T07:51:08.547+00:00

121069-staysignedin.png

We are using Microsoft Oauth2.0 for our app. It shows 'Stay signed in' page.
In this page, we can click Yes and/or No multiple times. When I click No twice after few seconds, same request is post.
121163-requests-from-ms.png

We are preventing the login if same request came to block replay attack. So user fails to login.
Is there any way to restrict to click the buttons multiple times?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.