Commit Graph

13 Commits

Author SHA1 Message Date
35ea8cc3e9 Share session cookies across www and app subdomains
Groundwork for moving the app to app.qrmaster.net: the session has to survive the
host change from www.qrmaster.net to app.qrmaster.net.

- Add COOKIE_DOMAIN and apply it to the auth, CSRF, attribution and OAuth flow
  cookies. Honoured only in production, because browsers reject dotted domains on
  localhost - a prod .env copied into a dev environment would otherwise break
  every login instead of just ignoring the value.
- Expire both the host-only and the domain-scoped variant on logout. Next's
  ResponseCookies is keyed by cookie name and rewrites the entire set-cookie
  header from its internal map on every set(), so the two variants must be
  appended manually - otherwise one overwrites the other and the surviving stale
  cookie keeps the user signed in.
- Pass COOKIE_DOMAIN as both build arg and runtime env: process.env is inlined
  into the Edge middleware bundle, so a runtime-only value would leave the
  middleware and the route handlers disagreeing about the cookie scope.

No behaviour change while COOKIE_DOMAIN is unset.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 19:01:14 +02:00
68c531a1d5 umami bugfix 2026-08-06 09:33:53 -05:00
Timo Knuth
c4fac0f726 SEO + Stripe 2026-04-27 17:10:30 +02:00
434b5954c1 solve permission problem 2026-04-12 14:51:37 -05:00
Timo Knuth
fe00bede47 Migration 2026-04-03 00:31:20 +02:00
Timo Knuth
76a76258e8 fixes 2026-01-26 19:51:00 +01:00
4569d89ab2 Fix: Add Facebook Pixel ID to Dockerfile 2026-01-26 00:23:15 +01:00
Timo Knuth
ce4c6ab985 hardcoded 2026-01-23 18:08:29 +01:00
Timo
c2988f1d50 chore: Update Dockerfile URLs to HTTPS and add test.md. 2026-01-01 20:28:36 +01:00
Timo
8acfb6c544 localhost change 2026-01-01 20:24:18 +01:00
Timo
91313ac7d5 footer+responsivenes 2026-01-01 20:18:45 +01:00
82ea760537 Final 2025-12-31 17:45:49 +01:00
Timo Knuth
5262f9e78f Initial commit - QR Master application 2025-10-13 20:19:18 +02:00