> Override the Host header to be equal to GTM-123456.fps.goog. Allow all cookies and query strings to be forwarded.
Did a security team review this? This leaks session cookies for your domain to Google in a way GTM did not previously capture.
Did a security team review this? This leaks session cookies for your domain to Google in a way GTM did not previously capture.
Only if you set up your session handler to emit cookies that apply to all subdomains instead of using the __Host- prefix and the SameSite=strict attribute [1].
[1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Se...
It's weird that the document specifically says "all cookies" - that gives GTM access to every cookie sent to your application.