Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

set sameSite to lax when allowing insecure cookies #1078

Merged
merged 1 commit into from
Apr 26, 2024

Conversation

nsarrazin
Copy link
Collaborator

The ALLOW_INSECURE_COOKIES flag wasn't working properly since we had strict sameSite policy.

Now when you ALLOW_INSECURE_COOKIES=true you get secure:false and sameSIte: "lax"

@nsarrazin nsarrazin added bug Something isn't working back This issue is related to the Svelte backend or the DB labels Apr 26, 2024
@nsarrazin nsarrazin merged commit bc30bd1 into main Apr 26, 2024
3 checks passed
@nsarrazin nsarrazin deleted the fix/samesite_lax_when_insecure branch April 26, 2024 10:26
ice91 pushed a commit to ice91/chat-ui that referenced this pull request Oct 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
back This issue is related to the Svelte backend or the DB bug Something isn't working
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant