Skip to content

GitLab

  • Menu
Projects Groups Snippets
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Sign in / Register
  • erp5 erp5
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Merge requests 141
    • Merge requests 141
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Jobs
  • Commits
Collapse sidebar
  • nexedi
  • erp5erp5
  • Merge requests
  • !802

Closed
Created Nov 21, 2018 by Jérome Perrin@jeromeOwner
  • Report abuse
Report abuse

WIP: Improve authentication cookies

  • Overview 10
  • Commits 1
  • Pipelines 1
  • Changes 4

The point of this MR is to make use of the SameSite extended cookie attribute that's supported in most browsers and in Zope.

This is in order to add extra protection against cross-origin requests as a way to fix #20181019-3CB56B.

In its current form, it breaks officejs which uses cross origin cookies.

Assignee
Assign to
Reviewer
Request review from
Time tracking
Source branch: fix/auth-cookies
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7