Include credentials when making request to action /secrets#1882
Merged
Include credentials when making request to action /secrets#1882
/secrets#1882Conversation
duranb
reviewed
Feb 23, 2026
duranb
requested changes
Feb 23, 2026
Collaborator
duranb
left a comment
There was a problem hiding this comment.
Do you mind updating the test.yml file as well to include the new env vars?
Contributor
Author
Done. So many updates required for env var additions.. |
Collaborator
Thanks! I know... |
…dd new backend env vars to docker-compose.
c88edeb to
5590714
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
___REQUIRES_AERIE_PR___="1784"Include cookie credentials when making a request to the
secretsendpoint of the action server to support forwarding of cookies (includinghttpOnlycookies) that may be required by actions for external authentication purposes.Credential inclusion is gated behind a new
PUBLIC_ACTION_INCLUDE_CREDENTIALSenvironment variable (defaultfalse). When set totrue, the UI sendscredentials: 'include'on action server requests, allowing the browser to attach cookies. This is opt-in to avoid breaking cross-origin deployments that don't haveACTION_CORS_ALLOWED_ORIGINconfigured on the action server.See backend PR for more details and testing procedure.