# Dropbox and Box thumbnails returning 401 Unauthorized

**URL:** <https://community.transloadit.com/t/dropbox-and-box-thumbnails-returning-401-unauthorized/15781>\
**Category:** Uppy\
**Created:** [July 15, 2021, 7:29am UTC](https://community.transloadit.com/t/dropbox-and-box-thumbnails-returning-401-unauthorized/15781 "2021-07-15T07:29:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bherrero](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/bherrero/32/446_2.png) [@bherrero](https://community.transloadit.com/u/bherrero)\
**Post date:** [July 15, 2021, 7:29am UTC](https://community.transloadit.com/t/dropbox-and-box-thumbnails-returning-401-unauthorized/15781/1 "2021-07-15T07:29:32Z")

</div>

Hi!  
We’ve been using Uppy for a while but we hadn’t updated it since almost half a year ago. We use companion and integration with Dropbox was working fine.

However, after updating to the latest version of both client and companion server (we use standalone), the thumbnails after adding an image are failing. It happens with both Dropbox and Box and only when using Chrome. When they try to request the thumbnail from the companion URL as `https://companion-url/thumbnail/827563117593` they return a 401 Unauthorized.

Our `companion-url`‘s domain differs from our clients’ domains but it was working with no issues before. I’m convinced is CORS related but I haven’t found the proper config to sort this out yet.

Any idea of what could we missing?

Edit: I’ve found this [post](https://community.transloadit.com/t/dropbox-image-thumbnail-issue-in-chrome/15418) mentioning the same issue. Anyone has sorted this out?

Thanks

---

<div class="post-metadata">

**Author:** ![bherrero](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/bherrero/32/446_2.png) [@bherrero](https://community.transloadit.com/u/bherrero)\
**Post date:** [July 16, 2021, 12:07am UTC](https://community.transloadit.com/t/dropbox-and-box-thumbnails-returning-401-unauthorized/15781/2 "2021-07-16T00:07:28Z")

</div>

Seems like `SameSite` wasn’t added to the cookies so adding it along with `security: true` made the trick.

```auto
const addToCookies = (res, token, companionOptions, authProvider, prefix) => {
    const cookieOptions = {
        maxAge: 1000 * EXPIRY,
        httpOnly: true,
        sameSite: 'none', // fix to show thumbnails on Chrome
        security: true, // fix to show thumbnails on Chrome
    };
    if (companionOptions.cookieDomain) {
        cookieOptions.domain = companionOptions.cookieDomain;
    }
    // send signed token to client.
    res.cookie(`${prefix}--${authProvider}`, token, cookieOptions);
};

```

In our case, given that Companion’s domain is different from our clients’ we need to set sameSite to none.

---

<div class="post-metadata">

**Author:** ![bherrero](https://yyz2.discourse-cdn.com/flex032/user_avatar/community.transloadit.com/bherrero/32/446_2.png) [@bherrero](https://community.transloadit.com/u/bherrero)\
**Post date:** [July 19, 2021, 3:58am UTC](https://community.transloadit.com/t/dropbox-and-box-thumbnails-returning-401-unauthorized/15781/3 "2021-07-19T03:58:55Z")

</div>

There’s actually a typo and it’s `secure: true` instead of `security: true`.
