mirror of
https://github.com/MODSetter/SurfSense.git
synced 2026-06-26 21:39:43 +02:00
fix(auth):harden session cookie transport
This commit is contained in:
parent
9b127a8533
commit
fbecbb98b5
3 changed files with 53 additions and 13 deletions
|
|
@ -807,6 +807,7 @@ allowed_origins.extend(
|
|||
]
|
||||
)
|
||||
|
||||
app.add_middleware(CsrfOriginMiddleware)
|
||||
app.add_middleware(
|
||||
CORSMiddleware,
|
||||
allow_origins=allowed_origins,
|
||||
|
|
@ -821,7 +822,6 @@ app.add_middleware(
|
|||
# FRONTEND_URL to BACKEND_URL.
|
||||
max_age=86400,
|
||||
)
|
||||
app.add_middleware(CsrfOriginMiddleware)
|
||||
|
||||
# Password / email-based auth routers are only mounted when not running in
|
||||
# Google-OAuth-only mode. Mounting them in OAuth-only prod previously left
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue