I am working on Angular 2 / Django Project. Each project is running on a specific port.
When making a post to /login
route, server returns seesionid
and csrftoken
cookies. Javascript code can't access both returned cookies and they don't apear on chrome developer tool:
Response:
Access-Control-Allow-Credentials:true
Access-Control-Allow-Origin:http://localhost
Allow:POST, OPTIONS
Date:Tue, 04 Apr 2017 14:47:31 GMT
Server:WSGIServer/0.2 CPython/3.5.2
Set-Cookie:csrftoken=ITzlkMrTtSYcmlNQANFvxQHlZ829qXe0tEblA3KOaKY6iRRB7Y3pYlvdcZNSpDcv; expires=Tue, 03-Apr-2018 14:47:31 GMT; Max-Age=31449600; Path=/
Set-Cookie:sessionid=d5v1mri12bniyvyqqt55ar8mfl9mr2jk; expires=Tue, 18-Apr-2017 14:47:31 GMT; HttpOnly; Max-Age=1209600; Path=/
Vary:Accept, Cookie, Origin
X-Frame-Options:SAMEORIGIN