-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Open
Labels
featNew feature or request.New feature or request.
Description
Preflight checklist
- I could not find a solution in the existing issues, docs, nor discussions.
- I agree to follow this project's Code of Conduct.
- I have read and am following this repository's Contribution Guidelines.
- I have joined the Ory Community Slack.
- I am signed up to the Ory Security Patch Newsletter.
Ory Network Project
No response
Describe your problem
We want to limit the exposure of Ory Hydras CSRF cookies.
Describe your ideal solution
We would like to configure the Path part of each CSRF cookie.
Currently, the Path is not set explicitly, which exposes the cookie to all systems under that domain.
One or more configuration fields could be introduced following the solution for configuring the session cookie path.
Workarounds or alternatives
Proxying calls to Hydra and re-writing the cookie headers to the correct values.
Version
v25.4.0
Additional Context
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
featNew feature or request.New feature or request.