You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We are using an insecure cookie policy that is setting cookies for the entire abandontech domain. Instead, we should only set cookies for the domain that abandonauth is hosted on. This should be possible by removing any explicit domain we are setting on cookies.
We also need to ensure we are using a secure cookie policy, we should still use secure=True and httponly=True in the UI response for setting cookies. Ideally, we can remove the separate cookie logic for debug mode versus prod deploy after we remove the explicit domain.
The text was updated successfully, but these errors were encountered:
Summary
We are using an insecure cookie policy that is setting cookies for the entire abandontech domain. Instead, we should only set cookies for the domain that abandonauth is hosted on. This should be possible by removing any explicit domain we are setting on cookies.
We also need to ensure we are using a secure cookie policy, we should still use
secure=True
andhttponly=True
in the UI response for setting cookies. Ideally, we can remove the separate cookie logic for debug mode versus prod deploy after we remove the explicit domain.The text was updated successfully, but these errors were encountered: