Join Slack
Powered by
Q: what's the purpose of setting the kratos cookie...
# talk-kratos
a
astonishing-psychiatrist-64556
11/17/2023, 11:44 PM
Q: what's the purpose of setting the kratos cookie domain to something broader than the domain that kratos itself is running on? Don't those cookies only need to go to kratos? Other services never need to read them, correct?
astonishing-psychiatrist-64556
11/17/2023, 11:45 PM
I'm mainly talking about the advice on this page:
https://www.ory.sh/docs/kratos/guides/multi-domain-cookies
When would someone need it?
astonishing-psychiatrist-64556
11/18/2023, 5:35 AM
I'm guessing one reason might be so oathkeeper can access the cookie on different subdomains?
w
wide-dawn-74672
11/19/2023, 8:56 AM
So other services like a backend will be sent the cookie so they can introspect/authenticate the user
wide-dawn-74672
11/19/2023, 8:57 AM
by setting the domain broader all subdomains will be sent the cookie allowing services on these domain to auth the user
2
Views
Open in Slack
Previous
Next