Actions
Bug #21445
closedJSESSIONID cookie should have a SameSite policy
Pull Request:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
Checked
Regression:
Description
https://caniuse.com/mdn-http_headers_set-cookie_samesite_lax_default
Only some modern browsers have a default lax policy, we should provide one to prevent trivial CSRF against the internal API.
Actions