Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Register
  • Sign in
  • erp5 erp5
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Merge requests 142
    • Merge requests 142
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Jobs
  • Commits
Collapse sidebar
  • nexedinexedi
  • erp5erp5
  • Merge requests
  • !802

WIP: Improve authentication cookies

  • Review changes

  • Download
  • Patches
  • Plain diff
Closed Jérome Perrin requested to merge jerome/erp5:fix/auth-cookies into master Nov 21, 2018
  • Overview 10
  • Commits 1
  • Pipelines 1
  • Changes 4

The point of this MR is to make use of the SameSite extended cookie attribute that's supported in most browsers and in Zope.

This is in order to add extra protection against cross-origin requests as a way to fix #20181019-3CB56B.

In its current form, it breaks officejs which uses cross origin cookies.

Assignee
Assign to
Reviewers
Request review from
Time tracking
Source branch: fix/auth-cookies
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7