mirror of
https://github.com/NodeBB/NodeBB.git
synced 2025-10-26 08:36:12 +01:00
feat: cookie SameSite property
More information: https://tools.ietf.org/html/draft-ietf-httpbis-cookie-same-site-00#section-4.1.1 https://web.dev/samesite-cookies-explained/
This commit is contained in:
@@ -164,6 +164,9 @@ Configs.cookie = {
|
||||
cookie.path = relativePath;
|
||||
}
|
||||
|
||||
// Ideally configurable from ACP, but cannot be "Strict" as then top-level access will treat it as guest.
|
||||
cookie.sameSite = 'Lax';
|
||||
|
||||
return cookie;
|
||||
},
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user