<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[SetCookie Domain is too broad for the cookies to work]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I've been trying to get FusionAuth working to authenticate a system built with NextJS using the react-sdk.</p>
<p dir="auto">I've managed to integrate the two locally (using the localhost domain) and that works just fine, but when I try and use it on a fully qualified staging domain (<a href="http://staging.example.co.uk" rel="nofollow ugc">staging.example.co.uk</a>) with the hosted FusionAuth instance at (<a href="http://auth.example.co.uk" rel="nofollow ugc">auth.example.co.uk</a>) the cookies are blocked as the domain is <code>Domain=co.uk</code></p>
<p dir="auto">I've spotted the docs (here<br />
<a href="https://fusionauth.io/docs/apis/hosted-backend#prerequisites" rel="nofollow ugc">https://fusionauth.io/docs/apis/hosted-backend#prerequisites</a>) saying</p>
<p dir="auto"><code>FusionAuth will set the domain on these cookies to .example.com where example is the domain name that FusionAuth is serving from either from the domain or any subdomain, com is the top-level domain, and the . allows the cookie to match the domain and all subdomains.</code></p>
<p dir="auto">But this doesn't seem to be happening. At the moment I can't work out how it's setting that, is it related to the Authorized redirect/origin URLs specified in the application configuration? Or does it just work off where the FA instance is being hosted?</p>
<p dir="auto">Any help would be greatly appreciated!</p>
]]></description><link>https://fusionauth.io/community/forum/topic/2669/setcookie-domain-is-too-broad-for-the-cookies-to-work</link><generator>RSS for Node</generator><lastBuildDate>Fri, 06 Mar 2026 20:12:28 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/2669.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 02 May 2024 10:56:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to SetCookie Domain is too broad for the cookies to work on Fri, 03 May 2024 14:22:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="mention plugin-mentions-user plugin-mentions-a" href="https://fusionauth.io/community/forum/uid/2993">@fin</a> When you say the cookies are blocked, what error message are you getting?  What do you mean by blocked?</p>
]]></description><link>https://fusionauth.io/community/forum/post/7223</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/7223</guid><dc:creator><![CDATA[mark.robustelli]]></dc:creator><pubDate>Fri, 03 May 2024 14:22:00 GMT</pubDate></item></channel></rss>