If you self-host an AT Protocol PDS and want to run a blog like GreenGale on the same parent domain, you've probably hit this error:
Forbidden sec-fetch-site header "same-site"
This happens because the AT Protocol OAuth provider only allows cross-site
and none for the Sec-Fetch-Site header. When your blog and PDS share the
same parent domain (e.g. md.falasi.net and bsky.falasi.net), the browser
correctly sends same-site — and the PDS rejects it.
The Fix
Credit to mary-ext for identifying this fix upstream.
Find this file inside your PDS container:
node_modules/@atproto/oauth-provider/dist/router/create-authorization-page-middleware.js
Locate this line:
validateFetchSite(req, ['same-origin', 'cross-site', 'none']);
And change it to:
validateFetchSite(req, ['same-origin', 'same-site', 'cross-site', 'none']);
Then restart your PDS. That's it — OAuth will now work across subdomains of the same parent domain.
Making It Stick
This change will be overwritten whenever you update your PDS. Remember to re-apply the patch after each update until it lands officially upstream.
A proper fix is being tracked in the atproto repo — bluesky-social/atproto#4131.