remove afety: avoid setting cookie on known public suffix-like domains

This commit is contained in:
2026-04-19 13:32:17 +01:00
parent 26cfe4eb5b
commit ae61c8f661
+9 -9
View File
@@ -26,16 +26,16 @@ const PUBLIC_SUFFIX_BLOCKLIST = new Set([
const rootDomain = parts.slice(-2).join(".");
// 5. Safety: avoid setting cookie on known public suffix-like domains
const unsafeTlds = new Set([
"vercel.app",
"netlify.app",
"github.io",
"firebaseapp.com",
]);
// const unsafeTlds = new Set([
// "vercel.app",
// "netlify.app",
// "github.io",
// "firebaseapp.com",
// ]);
if (unsafeTlds.has(rootDomain)) {
return undefined;
}
// if (unsafeTlds.has(rootDomain)) {
// return undefined;
// }
return `.${rootDomain}`;
}