fix: set cookie domain for cross-subdomain authentication

In production, the session cookie needs to be shared across
subdomains (e.g., api.example.com and app.example.com).

- Add cookie_domain property to config (extracts parent domain)
- Set SameSite=None for cross-origin requests in production
- Update auth callback and logout to use cookie domain
- This fixes the login loop where session cookie wasn't sent
This commit is contained in:
Fusion
2026-05-18 23:33:59 +02:00
parent c067c03662
commit 58bf30ed15
3 changed files with 33 additions and 6 deletions
+2 -1
View File
@@ -1,9 +1,10 @@
from src.config import Settings
def build_cookie_options(settings: Settings) -> dict[str, str | bool]:
def build_cookie_options(settings: Settings) -> dict[str, str | bool | None]:
return {
"httponly": True,
"secure": settings.cookie_secure,
"samesite": settings.cookie_samesite,
"domain": settings.cookie_domain,
}