fix: use auto cookie_secure to fix SSO invalid state parameter

The session cookie was not sent back on HTTP requests because
cookie_secure was hardcoded to true, causing OAuth2 state mismatch.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Serreau Jovann
2026-03-20 10:00:34 +01:00
parent 7023ee7fe0
commit c21f28a4d6

View File

@@ -10,7 +10,7 @@ framework:
session: session:
name: crm_session name: crm_session
cookie_lifetime: 3600 cookie_lifetime: 3600
cookie_secure: true cookie_secure: auto
#esi: true #esi: true
#fragments: true #fragments: true