Resolve cookie configuration per request
Signed-off-by: Marcus Eide <eide@spotify.com>
This commit is contained in:
@@ -5,4 +5,6 @@
|
||||
CookieConfigurer can optionally return the `SameSite` cookie attribute.
|
||||
CookieConfigurer now requires an additional argument `appOrigin` - the origin URL of the app - which is used to calculate the `SameSite` attribute.
|
||||
defaultCookieConfigurer returns the `SameSite` attribute which defaults to `Lax`. In cases where an auth-backend is running on a different domain than the App, `SameSite=None` is used - but only for secure contexts. This is so that cookies can be included in third-party requests.
|
||||
OAuthAdapterOptions has been modified to require additional arguments, `baseUrl`, `cookieConfigurer` and `cookieConfig`.
|
||||
|
||||
OAuthAdapterOptions has been modified to require additional arguments, `baseUrl`, and `cookieConfigurer`.
|
||||
OAuthAdapter now resolves cookie configuration using its supplied CookieConfigurer for each request to make sure that the proper attributes always are set.
|
||||
|
||||
Reference in New Issue
Block a user