Disable SESSION_COOKIE_DOMAIN
in local environment
#319
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
In Safari, in the context of a local environment, there seems to occur a collision between the anti CSRF mechanism and the
SESSION_COOKIE_DOMAIN
value, for Talos as a tool is intended to be used with a multiple project mentality. Hardcoding theSESSION_COOKIE_DOMAIN
aslocalhost
for all projects currently renders ineffective any attempt to log in to any Django admin, but the first Django admin one has ever logged in to, with said browser.The first solution that comes to mind is to disable
SESSION_COOKIE_DOMAIN
locally.