Repository navigation
How to create session cookie ? #4071
Unanswered
brianp-das
asked this question in
Q&A
Replies: 1 comment 1 reply
|
Hey! If you want a session-only cookie (no Max-Age/Expires), you should set If you set Try switching to |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hello everyone,
I'm currently implementing SSO for several apps, and one of the requirements is a "remember me" feature.
Persistent Session: If the user checks the "remember me" option, my IDP sets remember=true and remember_for=7200 in the request to the Hydra Accept Login endpoint. This correctly creates a persistent cookie.
Session-Only: However, if the user does not check this option, we expect Hydra to return a session-only cookie. This should ensure the cookie is cleared when the browser is closed.
It seems Hydra does not provide a straightforward way to create a pure session cookie (one without a Max-Age or Expires attribute). I have tried setting remember=true with remember_for=0, but Hydra still creates a persistent cookie with a Max-Age defaulted to 720h (the ttl.authentication_session value).
I might be missing something, but the official Ory documentation doesn't seem to mention how to achieve a non-persistent session cookie.
Does anyone have experience with this or know of a workaround?
Thanks,
All reactions