Add sameSite policy in cookie management in server side

pull/2895/head
Féry Mathieu (Mathius) 3 years ago
parent 8e4959a621
commit 09a585c93b
No known key found for this signature in database
GPG Key ID: F9CCC80C18A59037

@ -17,7 +17,8 @@ struct Invidious::User
value: sid,
expires: Time.utc + 2.years,
secure: SECURE,
http_only: true
http_only: true,
samesite: HTTP::Cookie::SameSite::Strict
)
end
@ -30,7 +31,8 @@ struct Invidious::User
value: URI.encode_www_form(preferences.to_json),
expires: Time.utc + 2.years,
secure: SECURE,
http_only: false
http_only: false,
samesite: HTTP::Cookie::SameSite::Strict
)
end
end

Loading…
Cancel
Save