-
-
Notifications
You must be signed in to change notification settings - Fork 236
Relax the session cookie from SameSite=Strict to Lax #2471
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
I'm not sure if this is a good change, as we lower the security. However, I'm not that confident with this cookie option and don't feel like overseeing all the implications. |
|
I don't think there will be any issues using
Using it will allow to users to use direct links to inner pages (we want the authentication cookie to be sent in this case, to avoid the login page). |
|
I tend towards the " |
Signed-off-by: DL6ER <[email protected]>
|
Rebased on latest |
|
@yubiuser what do you say? I'm not going to merge this against your objections if they still hold, I can understand it but I, personally, think it's fine. I have not been thinking long enough possible implications when I wrote this initially. @rdwebdesign is right that this is a breaking change because PHP is doing what we want to do in this PR as default |
|
If the two of you are good with the change I don't have objections. Esp. when
__ Did you consider my suggestion
|
|
If you think we should allow users to freely set this option, personally I think we should set |
|
Sorry, I did not see the two comments thus far. I don't think an option is useful here, it's rather unlikely that any user will really change it. |
|
Yeah... I don't think we need another option here. |
|
This pull request has been mentioned on Pi-hole Userspace. There might be relevant details there: https://discourse.pi-hole.net/t/pi-hole-ftl-v6-2-3-released/80593/1 |
What does this implement/fix?
Follow-up and possible solution (yet undecided!) on #2470
Related issue or feature (if applicable): Fixes #2470
Pull request in docs with documentation (if applicable): N/A
By submitting this pull request, I confirm the following:
git rebase)Checklist:
developmentalbranch.