Page MenuHomePhabricator

[web] Migrate cookies to redux
ClosedPublic

Authored by michal on Sep 25 2023, 7:05 AM.
Tags
None
Referenced Files
F3551170: D9287.id32308.diff
Thu, Dec 26, 7:15 PM
F3551165: D9287.id31401.diff
Thu, Dec 26, 7:15 PM
F3551161: D9287.id.diff
Thu, Dec 26, 7:15 PM
F3543936: D9287.id32307.diff
Thu, Dec 26, 11:41 AM
F3539036: D9287.diff
Thu, Dec 26, 12:03 AM
Unknown Object (File)
Wed, Dec 25, 5:38 PM
Unknown Object (File)
Nov 15 2024, 6:36 AM
Unknown Object (File)
Nov 11 2024, 10:08 PM
Subscribers

Details

Summary

ENG-4767

We want to migrate the browser cookies to redux. An explanation why we decided is in ENG-4347 and on Notion. We do the migration on the client after setting the cookie to httpOnly: false on the keyserver. This is normally not recommended because of XSS, but if our end goal is moving the cookie to redux, it will be accesible to js anyway, so there shouldn't be any issue with this. If the attacked can execute any js on the client they can still make authenticated calls to the keyserver/services (for services we keep commAccessToken in redux anyway).

Test Plan

Run the migration, check if the cookie was stored in redux

Diff Detail

Repository
rCOMM Comm
Lint
No Lint Coverage
Unit
No Test Coverage