Skip to content

Mark __Host- cookie deletions as Secure so https sign-out works - #71

Merged
nlundee merged 1 commit into
mainfrom
fix/host-cookie-delete
Sep 25, 2026
Merged

nlundee merged 1 commit into
mainfrom
fix/host-cookie-delete

Conversation

@nlundee

@nlundee nlundee commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

On https the session and return-to cookies carry the __Host- prefix. That prefix requires the Secure attribute, so a deletion without it fails. Hono refuses to write the header, which crashed logout and any callback that failed the state check. Browsers would also ignore such a deletion and leave the cookie in place.

Pass the same secure flag used when the cookies are set. Tests now run the auth routes against an https origin.

On https the session and return-to cookies carry the __Host- prefix.
That prefix requires the Secure attribute, so a deletion without it
fails. Hono refuses to write the header, which crashed logout and any
callback that failed the state check. Browsers would also ignore such
a deletion and leave the cookie in place.

Pass the same secure flag used when the cookies are set. Tests now run
the auth routes against an https origin.
@nlundee
nlundee merged commit 8639267 into main Sep 25, 2026
4 checks passed
@nlundee
nlundee deleted the fix/host-cookie-delete branch September 25, 2026 09:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant