58bf30ed15
In production, the session cookie needs to be shared across subdomains (e.g., api.example.com and app.example.com). - Add cookie_domain property to config (extracts parent domain) - Set SameSite=None for cross-origin requests in production - Update auth callback and logout to use cookie domain - This fixes the login loop where session cookie wasn't sent