Commit fe8d691
fix: set cookies alongside header when SendJWTHeader is enabled (#262)
* fix: set cookies alongside header when SendJWTHeader is enabled
When SendJWTHeader is true, now sets both the JWT header AND cookies.
This fixes OAuth authentication flows where HTTP headers don't survive
browser redirects. Cookies are needed for the OAuth callback to complete
successfully, while headers are still set for direct API calls.
Fixes umputun/remark42#1877
* test: add XSRF cookie value assertion in SendJWTHeader test
verify XSRF-TOKEN cookie value matches claims ID for consistency
with TestJWT_SetWithDomain
---------
Co-authored-by: Umputun <umputun@gmail.com>1 parent b18b2ea commit fe8d691
4 files changed
Lines changed: 16 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
249 | 249 | | |
250 | 250 | | |
251 | 251 | | |
252 | | - | |
| 252 | + | |
| 253 | + | |
253 | 254 | | |
254 | 255 | | |
255 | 256 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
263 | 263 | | |
264 | 264 | | |
265 | 265 | | |
266 | | - | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
267 | 272 | | |
268 | 273 | | |
269 | 274 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
266 | 266 | | |
267 | 267 | | |
268 | 268 | | |
269 | | - | |
| 269 | + | |
| 270 | + | |
270 | 271 | | |
271 | 272 | | |
272 | 273 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
263 | 263 | | |
264 | 264 | | |
265 | 265 | | |
266 | | - | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
267 | 272 | | |
268 | 273 | | |
269 | 274 | | |
| |||
0 commit comments