fix: Use Lax mode for OAuth redirect cookies (#1162)

OAuthing was resulting in an error, because Strict
cookies are not sent on redirects.
This commit is contained in:
Kyle Carberry
2022-04-25 20:42:18 +00:00
committed by GitHub
parent a201610761
commit 759fa5f626
+2 -2
View File
@@ -71,7 +71,7 @@ func ExtractOAuth2(config OAuth2Config) func(http.Handler) http.Handler {
Value: state,
Path: "/",
HttpOnly: true,
SameSite: http.SameSiteStrictMode,
SameSite: http.SameSiteLaxMode,
})
// Redirect must always be specified, otherwise
// an old redirect could apply!
@@ -80,7 +80,7 @@ func ExtractOAuth2(config OAuth2Config) func(http.Handler) http.Handler {
Value: r.URL.Query().Get("redirect"),
Path: "/",
HttpOnly: true,
SameSite: http.SameSiteStrictMode,
SameSite: http.SameSiteLaxMode,
})
http.Redirect(rw, r, config.AuthCodeURL(state, oauth2.AccessTypeOffline), http.StatusTemporaryRedirect)