• bitjunkie@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    1
    ·
    4 months ago

    I’m curious how this will affect OAuth (if at all). Does it use an offsite cookie to remember the session, or is that only created after it redirects back to the site that initiated the login?

    • version_unsorted@lemm.ee
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 months ago

      I my experience it generally breaks it. Leveraging cookies on the auth domain is fine, but once you are redirected to another domain, that application needs to take the access and refresh tokens and manage reauthentication as a background process. Simply don’t store those things as cookies though.

      • bitjunkie@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 months ago

        Yeah that’s kind of what I was getting at. It’s been a while since I’ve worked with it so I couldn’t remember if it used cookies for the token exchange or some other mechanism.