Announcements

Help Wizard

Step 1

NEXT STEP

FAQs

Please see below the most popular frequently asked questions.

Loading article...

Loading faqs...

VIEW ALL

Ongoing Issues

Please see below the current ongoing issues which are under investigation.

Loading issue...

Loading ongoing issues...

VIEW ALL

Is there a way to implement the web playback sdk with spotify auth token stored in http only cookie

Is there a way to implement the web playback sdk with spotify auth token stored in http only cookie

Plan

Premium

Country

France

Device

Web dev, widget, Pc 

Operating System

Windows

 

My Question or Issue

Hi, i'm implementing spotify auth token inside my app. We put it inside the cookie of browser, with flag http-only , then the frontend can't read the token and we read it only server side, so it can't be sniff and it's more secure. 

But here our problem is we need to implement spotify web playback sdk, who needs the token provided in frontend to work. Then it makes it not possible with the cookie flagged http-only, we have to make it visible.

Can we implement the widget a way it would read the auth token in cookie, flagged http-only , on server side ?  like with a special cookie_key , that the widget would request to work ? or does that special key exist already ?  Then we could keep the token out of front, and by caling the callback just set the cookie 🙂 

 

Have a nice day ! 

Reply
0 Replies

Suggested posts

Staff
Let's introduce ourselves!

Hey there you,   Yeah, you! 😁   Welcome - we're glad you joined the Spotify Community!   While you here, let's have a fun game and get…

Staff
ModeratorStaff / Moderator/ 3 years ago  in Social & Random

Type a product name