some-scooter-3723
01/13/2022, 5:42 PMWe do not recommend running them on separate subdomains, e.g. <https://kratos.my-website/> and <https://secureapp.my-website/>.
Why do you have that recommendation? just currently I set it up like that way. In case I continue with that way, is there any advice for me to get rid of csrf issue?
Thanks so much.bright-vr-21909
01/13/2022, 5:02 PMdamp-secretary-66941
01/12/2022, 2:35 PMkratos
but this same is available on server side?lively-beard-47107
01/12/2022, 2:17 PMenough-dog-88171
01/12/2022, 10:24 AMmodern-controller-1963
01/12/2022, 4:55 AMdry-energy-23478
01/11/2022, 8:27 AMenough-winter-51484
01/10/2022, 7:35 PMbright-vr-21909
01/10/2022, 6:53 PMearly-fountain-60696
01/10/2022, 10:18 AMfuture-bear-25158
01/08/2022, 8:59 AMbulky-architect-22083
01/08/2022, 8:23 AMbitter-arm-6486
01/07/2022, 4:41 PMmicroscopic-oyster-60915
01/07/2022, 3:36 PMearly-fountain-60696
01/07/2022, 3:07 PMwooden-finland-38637
01/07/2022, 1:04 PMmelodic-easter-54717
01/07/2022, 12:02 PMbrainy-winter-45330
01/06/2022, 6:02 PMdazzling-toothbrush-97662
01/06/2022, 3:26 PMERR_TOO_MANY_REDIRECTS
I changed lots of configs, but couldn’t fix that.high-optician-2097
bitter-arm-6486
01/04/2022, 8:21 PMhigh-optician-2097
high-optician-2097
bumpy-secretary-36855
12/29/2021, 10:21 PMkratos:4434
AND my localhost where the URL should be localhost:4434
?some-scooter-3723
12/29/2021, 2:11 PMpre persist
, how can I do that? there is no document / example about this configquiet-psychiatrist-3449
12/26/2021, 5:49 PM/schemas
endpoint is open to the public, yet it doesn't even exist for the admin API. Since I want to use Kratos for customer authentication, as well as employee authentication and partners authentication, I would like to "obfuscate" the available identity schemas. People with access to the public Kratos API shouldn't be able to see what kind of internal schemas we use. Why is it even public, yet not available under the admin API? I'm a bit confused here, since I'm not really all too versed in IAM. Are schemas supposed to be public to everybody? Is security though obfuscation not a thing in IAM? (Not telling the world what kind of authentication structure your company has should be the default, shouldn't it?) Would be great if somebody could explain the reasoning to me here 🙂incalculable-psychiatrist-10067
12/23/2021, 3:53 PMelegant-sandwich-40072
12/23/2021, 8:37 AMsome-scooter-3723
12/20/2021, 6:24 PMearly-fountain-60696
12/20/2021, 5:06 PM