From 51a7e85858dc8841871de249fe6baa441dd28be4 Mon Sep 17 00:00:00 2001 From: Peter Maquiran Date: Tue, 21 Apr 2026 20:51:23 +0100 Subject: [PATCH] add same origin to cookies --- app/api/auth/callback/route.ts | 2 +- app/api/session/route.ts | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/app/api/auth/callback/route.ts b/app/api/auth/callback/route.ts index a8b316d..bee5e84 100644 --- a/app/api/auth/callback/route.ts +++ b/app/api/auth/callback/route.ts @@ -51,8 +51,8 @@ export async function GET(req: Request) { secure: isHttps, sameSite: "none", path: "/", + ...(env.COOKIE_DOMAIN ? { domain: env.COOKIE_DOMAIN } : {}), maxAge: data.expires_in, - ...(BASE_URL ? { BASE_URL } : {}), }); return res; diff --git a/app/api/session/route.ts b/app/api/session/route.ts index dbd93b8..156069e 100644 --- a/app/api/session/route.ts +++ b/app/api/session/route.ts @@ -1,3 +1,4 @@ +import { env } from "@/lib/env"; import { NextResponse } from "next/server"; export async function POST(req: Request) { @@ -9,6 +10,7 @@ export async function POST(req: Request) { httpOnly: true, secure: true, sameSite: "none", + ...(env.COOKIE_DOMAIN ? { domain: env.COOKIE_DOMAIN } : {}), path: "/", });