3 ms·
This is specific to when you run a deployment where a user is authenticated cross domain with a authentication server. If a user wants to sign in to foo.com th
by jonkoops 2y ago
This is specific to when you run a deployment where a user is authenticated cross domain with a authentication server.
If a user wants to sign in to foo.com through auth.com it is not possible for foo.com to know if the user has a session, so it needs to redirect the user to auth.com to understand if the user has a session. Previously this could be handled by embedding an iframe into foo.com with auth.com that can read the session cookie, this is no longer possible due to cookie protection.
Also if a user is signed into auth.com and foo.com, and then signs out of auth.com it is not possible to detect the user has signed out, as foo.com cannot access cookies set on auth.com.