diff --git a/media_manager/auth/users.py b/media_manager/auth/users.py index a4abf81..3a0ce23 100644 --- a/media_manager/auth/users.py +++ b/media_manager/auth/users.py @@ -116,7 +116,9 @@ class RedirectingCookieTransport(CookieTransport): bearer_transport = BearerTransport(tokenUrl="auth/jwt/login") -cookie_transport = CookieTransport(cookie_max_age=LIFETIME) +cookie_transport = CookieTransport( + cookie_max_age=LIFETIME, cookie_samesite="lax", cookie_secure=False +) openid_cookie_transport = RedirectingCookieTransport(cookie_max_age=LIFETIME) bearer_auth_backend = AuthenticationBackend(