Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Register
  • Sign in
  • erp5 erp5
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Merge requests 142
    • Merge requests 142
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Jobs
  • Commits
Collapse sidebar
  • nexedinexedi
  • erp5erp5
  • Merge requests
  • !976

[erp5_core] Use SameSite=None cookie

  • Review changes

  • Download
  • Patches
  • Plain diff
Closed Romain Courteaud requested to merge romain/erp5:samesite into master Oct 31, 2019
  • Overview 2
  • Commits 1
  • Pipelines 0
  • Changes 1

The Chrome dev team plans to change the default cookie behaviour by setting the SameSite attribute to Lax.

This will break OfficeJS access for Chrome 80 users, as the cookie will not be send anymore when erp5 would be accessed from the external web site.

In order to keep the current functionalities, one quick solution is too manually set the SameSite value to None.

Of course, doing it would prevent to get all the benefits of the Lax value. But I believe we would have to finish MR138 to get it.

Assignee
Assign to
Reviewers
Request review from
Time tracking
Source branch: samesite
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7