Arize-ai / phoenix

AI Observability & Evaluation
https://docs.arize.com/phoenix
Other
3.88k stars 292 forks source link

[auth][oauth] set oauth2 state and nonce cookies with "lax" samesite policy #4685

Closed axiomofjoy closed 1 month ago

mikeldking commented 1 month ago

Why lax?

axiomofjoy commented 1 month ago

@mikeldking If the user is not yet authenticated with the OAuth2 IDP and has to sign in for the first time, strict cookies won't be sent back to the callback URL.

https://stackoverflow.com/a/42220786