fix: cross-subdomain SSO auto-login for *arr services
- Set Domain=.sami on session + CSRF cookies so browsers send them to all subdomains - This fixes Caddy forward_auth returning 401 for radarr/sonarr/prowlarr - Fix login URL concatenation bug (radarr.samilogin -> radarr.sami/login) - Fix getSetCookie() missing from _httpsFetch/_httpFetch response objects - Fix array/string handling for set-cookie header in session-handlers fallback - Refactor csrf-protection to createCSRFMiddleware() factory with cookieDomain support - Pass renewCSRFToken through middleware deps chain to TOTP route
This commit is contained in:
@@ -27,7 +27,8 @@ module.exports = function(ctx) {
|
||||
fetchT: ctx.fetchT,
|
||||
getServiceById: ctx.getServiceById,
|
||||
licenseManager: ctx.licenseManager,
|
||||
servicesStateManager: ctx.servicesStateManager
|
||||
servicesStateManager: ctx.servicesStateManager,
|
||||
renewCSRFToken: ctx.middlewareResult?.renewCSRFToken
|
||||
};
|
||||
|
||||
const { getAppSession, appSessionCache } = initSessionHandlers(deps);
|
||||
|
||||
Reference in New Issue
Block a user