-
|
Hi, What is the purpose of the cookies with the "_LEGACY" suffix that are just a duplicate of the cookies w/ the same name but w/o the suffix ? Is there a way to disable the generation of these cookies? FYI, We're using Keycloak 14.0.0 . Regards, |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 6 replies
-
|
Hello,
Non-legacy cookies are used in 3rd party contexts, when KC cookies need to be accessed from another hostname, typically by the JS adapter. Legacy cookies are required as a workaround for older Apple devices that had a bug [1] in SameSite handling. Also, thanks to the variable Secure attribute the cookies are useful when running KC locally during development as SSL is not required in this case. However, they are inaccessible in 3rd party contexts. Thanks to this they don't possess any security risk, together with the Secure attribute when accessed externally, and HttpOnly attribute for any sensitive cookies. |
Beta Was this translation helpful? Give feedback.
Hello,
yes, there are still use cases for it. They have different attributes.
Non-legacy cookies are used in 3rd party contexts, when KC cookies need to be accessed from another hostname, typically by the JS adapter.
Legacy cookies are required as a workaround for older Apple devices that had a bug [1] in SameSite handling. Also, thanβ¦