Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove http-only cookie on gatekeepers #573

Closed
filippomc opened this issue Sep 12, 2022 · 0 comments · Fixed by #574
Closed

Remove http-only cookie on gatekeepers #573

filippomc opened this issue Sep 12, 2022 · 0 comments · Fixed by #574
Assignees
Labels
enhancement New feature or request scope:accounts
Milestone

Comments

@filippomc
Copy link
Collaborator

filippomc commented Sep 12, 2022

The gatekeeper sets the cookie to be http-only, so preventing the user information coming from the JWT token to be read from javascript in applications.

I think that reading the cookie from Javascript is really useful, so I'm for defaulting to http-only-cookie: false

@filippomc filippomc added enhancement New feature or request scope:accounts labels Sep 12, 2022
@filippomc filippomc added this to the v2.0.0 milestone Sep 12, 2022
@filippomc filippomc self-assigned this Sep 12, 2022
zsinnema added a commit that referenced this issue Sep 12, 2022
#573 default gk http-only-cookie false
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request scope:accounts
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant