fix: allow oauth_state token to be cross-domain (#40)

External OIDC providers won’t work with the current setup.
This commit is contained in:
Peter Olds 2025-01-12 13:27:06 -08:00 committed by GitHub
parent 51f6391ded
commit 9a12dab600
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -60,7 +60,8 @@ func OIDCLoginHandler(w http.ResponseWriter, r *http.Request) {
Value: state, Value: state,
MaxAge: 300, MaxAge: 300,
HttpOnly: true, HttpOnly: true,
SameSite: http.SameSiteStrictMode, SameSite: http.SameSiteNoneMode,
Secure: true,
Path: "/", Path: "/",
}) })