Need clarity on session state variable

Issue #969 resolved
Former user created an issue

Is there any specific purpose for including client-id in session_state variable generation?

Comments (8)

  1. John Bradley

    I recall that it something to do with multiple clients using the same origin in a multi tenant deployment. Breno or Naveen are more likely to remember.

  2. Michael Jones

    Breno de Medeiros explained it to me this way:

    "It is motivated by a privacy consideration. The assumption here is that multiple clients might be registered in the same UI (e.g., embedded widgets from different parties) and that there's an expectation not to share identifiers across apps that are not controlled by existing privacy settings."

  3. Log in to comment