# User management on two projects

**URL:** <https://community.weweb.io/t/user-management-on-two-projects/8148>\
**Category:** Ask us anything\
**Created:** [April 16, 2024, 2:49pm UTC](https://community.weweb.io/t/user-management-on-two-projects/8148 "2024-04-16T14:49:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Baris](https://avatars.discourse-cdn.com/v4/letter/b/ea666f/32.png) [@Baris](https://community.weweb.io/u/Baris)\
**Post date:** [April 16, 2024, 2:49pm UTC](https://community.weweb.io/t/user-management-on-two-projects/8148/1 "2024-04-16T14:49:46Z")

</div>

Hello, I’m relatively new to weweb. I want to create one app subdomain and one www subdomain for the landing page. For this purpose, I will create two projects. Is it possible to displaying different content on the landing page if the user has logged in on the app? I am using Xano auth. In other words, would the cookie from one be valid in the others? Thanks

---

<div class="post-metadata">

**Author:** ![Alexis](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/alexis/32/13248_2.png) [@Alexis](https://community.weweb.io/u/Alexis)\
**Post date:** [April 17, 2024, 7:53am UTC](https://community.weweb.io/t/user-management-on-two-projects/8148/2 "2024-04-17T07:53:56Z")

</div>

Do you mean you will have a weweb app on [app.mydomain.com](http://app.mydomain.com) and another weweb app on [www.mydomain.com](http://www.mydomain.com) ?

---

<div class="post-metadata">

**Author:** ![Baris](https://avatars.discourse-cdn.com/v4/letter/b/ea666f/32.png) [@Baris](https://community.weweb.io/u/Baris)\
**Post date:** [April 17, 2024, 11:23am UTC](https://community.weweb.io/t/user-management-on-two-projects/8148/3 "2024-04-17T11:23:05Z")

</div>

Yes, that’s correct. But… I guess it’s not possible?

---

<div class="post-metadata">

**Author:** ![Alexis](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/alexis/32/13248_2.png) [@Alexis](https://community.weweb.io/u/Alexis)\
**Post date:** [April 17, 2024, 12:41pm UTC](https://community.weweb.io/t/user-management-on-two-projects/8148/4 "2024-04-17T12:41:23Z")

</div>

To be honest I’m not sure about the current behavior 🤔

- The cookie we create is probably set on the sub domain, so it won’t be shared across subdomain
- This cookie is expected to be removed in the coming weeks as we will rework how we handle authentication
- I thought about using localstorage but it seems it cannot be shared easily across subdomains

I think you have two options here

1. Create yourself a cookie with javascript when your user login containing the token ([cookies.set](https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/API/cookies/set)), and apply your root domain in the cookie settings so it can be read by every subdomains, you should be able to read the cookie when available and set the token manually through the plugin action
2. More secure but more technical, if you want a cookie that is “http only” and “secure”, you will need the new option we plan to release, this options allow you to send cookies automatically with your requests, its useful for cookies created by the server ([set-cookie header](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie)), you will create this cookie on your login endpoint and so it will automatically be sent with all request from the browser to your Xano

---

<div class="post-metadata">

**Author:** ![Baris](https://avatars.discourse-cdn.com/v4/letter/b/ea666f/32.png) [@Baris](https://community.weweb.io/u/Baris)\
**Post date:** [April 17, 2024, 12:50pm UTC](https://community.weweb.io/t/user-management-on-two-projects/8148/5 "2024-04-17T12:50:02Z")

</div>

Thank you for the answer, option 2 makes sense and can solve the issue.
