diff --git a/backend/app/routers/auth.py b/backend/app/routers/auth.py index 84733e6..6d15928 100644 --- a/backend/app/routers/auth.py +++ b/backend/app/routers/auth.py @@ -19,6 +19,7 @@ APP_ENV = (os.getenv("APP_ENV") or os.getenv("ENVIRONMENT") or os.getenv("FASTAP IS_PRODUCTION = APP_ENV in {"prod", "production"} COOKIE_SECURE = True if IS_PRODUCTION else os.getenv("COOKIE_SECURE", "0") == "1" COOKIE_SAMESITE = (os.getenv("COOKIE_SAMESITE") or "lax").lower() +COOKIE_DOMAIN = (os.getenv("COOKIE_DOMAIN") or "").strip() or None if IS_PRODUCTION and not COOKIE_SECURE: raise RuntimeError("Secure session cookies are mandatory in production") @@ -33,6 +34,7 @@ def _set_session_cookie(response: Response, session_id: str): max_age=SESSION_TTL_SECONDS, secure=COOKIE_SECURE, path="/", + domain=COOKIE_DOMAIN, )