From 7e07f0ce567c966a663ed17e19fc91f92cde4e53 Mon Sep 17 00:00:00 2001 From: Dmitry S Date: Sun, 3 Oct 2021 17:27:22 -0400 Subject: [PATCH] (core) For grist_sid*_status cookie, remember to set the path Test Plan: Only tested manually that path is included. Reviewers: paulfitz Reviewed By: paulfitz Differential Revision: https://phab.getgrist.com/D3056 --- app/server/lib/Authorizer.ts | 1 + 1 file changed, 1 insertion(+) diff --git a/app/server/lib/Authorizer.ts b/app/server/lib/Authorizer.ts index e11bd3a5..13c29cdd 100644 --- a/app/server/lib/Authorizer.ts +++ b/app/server/lib/Authorizer.ts @@ -529,6 +529,7 @@ export function signInStatusMiddleware(req: Request, resp: Response, next: NextF httpOnly: false, // make available to client-side scripts expires, domain: getCookieDomain(req), + path: '/', sameSite: 'lax', // same setting as for grist-sid is fine here. })); }