Let's say you have the following cookie setter:
res.cookie('name', 'tobi', {
secure: true,
httpOnly: false,
sameSite: 'None',
domain: '.example1.com'
});
How would you need to change the domain
attribute to share the cookie with multiple domains, and not only with example1.com?
I've tried several options for the domain
attribute, but none worked:
domain: "'.example1.com','example2.com'"
domain: ['.example1.com','example2.com']
domain: "['.example1.com','example2.com']"
domain: ".example1.com", domain: "example2.com"
CodePudding user response:
None worked because it's simply not allowed:
Also, if your website is hosted on www.example1.com
, your server is only allowed to set cookies for either www.example1.com
or example1.com
(the latter meaning "example1.com and all subdomains").