0
0
Fork 0
mirror of https://github.com/go-gitea/gitea synced 2024-12-01 13:43:11 +01:00

Add missing SameSite settings for the i_like_gitea cookie (#16037)

The i_like_gitea cookie appears to be missing the SameSite settings. I think they
were present at some point but may have been removed in a merge.

This PR ensures that they are set.

Fix #15972

Signed-off-by: Andrew Thornton <art27@cantab.net>
This commit is contained in:
zeripath 2021-05-31 19:22:36 +01:00 committed by GitHub
parent 7a484c0788
commit cbf30830d2
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
3 changed files with 3 additions and 0 deletions

View file

@ -557,6 +557,7 @@ func Routes() *web.Route {
Gclifetime: setting.SessionConfig.Gclifetime, Gclifetime: setting.SessionConfig.Gclifetime,
Maxlifetime: setting.SessionConfig.Maxlifetime, Maxlifetime: setting.SessionConfig.Maxlifetime,
Secure: setting.SessionConfig.Secure, Secure: setting.SessionConfig.Secure,
SameSite: setting.SessionConfig.SameSite,
Domain: setting.SessionConfig.Domain, Domain: setting.SessionConfig.Domain,
})) }))
m.Use(securityHeaders()) m.Use(securityHeaders())

View file

@ -94,6 +94,7 @@ func InstallRoutes() *web.Route {
Gclifetime: setting.SessionConfig.Gclifetime, Gclifetime: setting.SessionConfig.Gclifetime,
Maxlifetime: setting.SessionConfig.Maxlifetime, Maxlifetime: setting.SessionConfig.Maxlifetime,
Secure: setting.SessionConfig.Secure, Secure: setting.SessionConfig.Secure,
SameSite: setting.SessionConfig.SameSite,
Domain: setting.SessionConfig.Domain, Domain: setting.SessionConfig.Domain,
})) }))

View file

@ -161,6 +161,7 @@ func WebRoutes() *web.Route {
Gclifetime: setting.SessionConfig.Gclifetime, Gclifetime: setting.SessionConfig.Gclifetime,
Maxlifetime: setting.SessionConfig.Maxlifetime, Maxlifetime: setting.SessionConfig.Maxlifetime,
Secure: setting.SessionConfig.Secure, Secure: setting.SessionConfig.Secure,
SameSite: setting.SessionConfig.SameSite,
Domain: setting.SessionConfig.Domain, Domain: setting.SessionConfig.Domain,
})) }))