My app looks like that:
- Client: Angular
- Web server: node.js + NestJS
- Login page: html document + jQqery served as a static by the server
- Auth mechanism: HttpOnly cookie
The user should fill the login form on localhost:3000/login
Then the request will sent to localhost:3000/api/login with the credentials.
After validation, the server should response with Set-cookie header and redirect to localhost:4200.
The HttpOnly cookie should be valid for both localhost:3000 and localhost:4200 domains.
What is the correct way to implement the redirect and set-cookie?