Skip to content

Commit 1e55b77

Browse files
committed
Set samesite cookie value to none
As requested by Bart (excuse my Dutch) Inkomende SAML assertions vallen altijd onder cross-site POSTs, en die worden geblokkeerd als je niet expliciet SameSite=none zet. Onze loadbalancer herschrijft cookies wel, maar alleen als ze zelf geen samesite zetten
1 parent c69fe9e commit 1e55b77

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

config/packages/framework.yaml

+1-1
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ framework:
1616
name: sess_selfservice
1717
cookie_httponly: true
1818
cookie_secure: true
19-
cookie_samesite: lax
19+
cookie_samesite: none
2020

2121
fragments: false
2222
error_controller: Surfnet\StepupSelfService\SelfServiceBundle\Controller\ExceptionController::show

0 commit comments

Comments
 (0)