Skip to content

Configuration of the csrf cookies paths #4059

@daniel-eichinger-snkeos

Description

Preflight checklist

Ory Network Project

No response

Describe your problem

We want to limit the exposure of Ory Hydras CSRF cookies.

Describe your ideal solution

We would like to configure the Path part of each CSRF cookie.

Currently, the Path is not set explicitly, which exposes the cookie to all systems under that domain.
One or more configuration fields could be introduced following the solution for configuring the session cookie path.

Workarounds or alternatives

Proxying calls to Hydra and re-writing the cookie headers to the correct values.

Version

v25.4.0

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    featNew feature or request.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions