Commit Graph

9 Commits

Author SHA1 Message Date
35ea8cc3e9 Share session cookies across www and app subdomains
Groundwork for moving the app to app.qrmaster.net: the session has to survive the
host change from www.qrmaster.net to app.qrmaster.net.

- Add COOKIE_DOMAIN and apply it to the auth, CSRF, attribution and OAuth flow
  cookies. Honoured only in production, because browsers reject dotted domains on
  localhost - a prod .env copied into a dev environment would otherwise break
  every login instead of just ignoring the value.
- Expire both the host-only and the domain-scoped variant on logout. Next's
  ResponseCookies is keyed by cookie name and rewrites the entire set-cookie
  header from its internal map on every set(), so the two variants must be
  appended manually - otherwise one overwrites the other and the surviving stale
  cookie keeps the user signed in.
- Pass COOKIE_DOMAIN as both build arg and runtime env: process.env is inlined
  into the Edge middleware bundle, so a runtime-only value would leave the
  middleware and the route handlers disagreeing about the cookie scope.

No behaviour change while COOKIE_DOMAIN is unset.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 19:01:14 +02:00
ca1e432f80 Clarity 2026-08-11 21:50:42 +02:00
d542f849aa TikTok V5 + Security 2026-07-11 22:09:10 +02:00
Timo Knuth
0b9c8d2a8f TikTok api 2026-07-02 13:06:50 +02:00
Timo Knuth
fb70b433c7 Industries 2026-03-31 18:46:01 +02:00
e6b19e7a1c search console SEO ableitungen 2026-03-23 19:01:52 -05:00
Timo Knuth
74d0b5e7f2 Hardcode+middleware 2026-01-23 20:48:09 +01:00
Timo Knuth
f31992b952 Wichige änderung an DB 2025-11-05 12:02:59 +01:00
Timo Knuth
5262f9e78f Initial commit - QR Master application 2025-10-13 20:19:18 +02:00