fix(auth): configurable SameSite cookie for cross-origin dev setup
Chrome 89+ schemeful same-site treats http://localhost and https://localhost as different sites, blocking SameSite=Strict cookies on cross-origin fetch (e.g. Vite on port 5173, API on port 7221). Fix: make CookieSameSite configurable per environment in JwtSettings. - Default: Strict (production) - appsettings.Development.json: None (allows cross-origin cookie in dev) - When SameSite=None, Secure is always forced (browser requirement) Revert the earlier Vite proxy approach in favour of this backend config. VITE_API_BASE_URL remains a freely configurable URL in .env.local. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
@@ -6,8 +6,7 @@ import { z } from 'zod';
|
||||
* once and only warns in development — production trusts the build-time env.
|
||||
*/
|
||||
const configSchema = z.object({
|
||||
// Empty string = use Vite proxy (same-origin); a full URL = direct mode.
|
||||
apiBaseUrl: z.union([z.literal(''), z.string().url()]),
|
||||
apiBaseUrl: z.string().url(),
|
||||
});
|
||||
|
||||
export type AppConfig = z.infer<typeof configSchema>;
|
||||
|
||||
Reference in New Issue
Block a user