fix(auth):harden session cookie transport

This commit is contained in:
Anish Sarkar 2026-06-24 03:55:39 +05:30
parent 9b127a8533
commit fbecbb98b5
3 changed files with 53 additions and 13 deletions

View file

@ -807,6 +807,7 @@ allowed_origins.extend(
]
)
app.add_middleware(CsrfOriginMiddleware)
app.add_middleware(
CORSMiddleware,
allow_origins=allowed_origins,
@ -821,7 +822,6 @@ app.add_middleware(
# FRONTEND_URL to BACKEND_URL.
max_age=86400,
)
app.add_middleware(CsrfOriginMiddleware)
# Password / email-based auth routers are only mounted when not running in
# Google-OAuth-only mode. Mounting them in OAuth-only prod previously left