Skip to content

Commit 5171678

Browse files
committed
Merge branch 'w/131.0/feature/enhance-salt-api-security-with-strict-samesite-policy' into tmp/octopus/w/132.0/feature/enhance-salt-api-security-with-strict-samesite-policy
2 parents d54ba5b + 8245148 commit 5171678

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

salt/metalk8s/addons/ui/deployed/ingress.sls

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -30,9 +30,7 @@ metadata:
3030
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
3131
# Add strict SameSite policy for Salt API
3232
nginx.ingress.kubernetes.io/configuration-snippet: |
33-
if ($proxy_host = "salt-api") {
34-
proxy_cookie_flags ~ SameSite=Strict Secure HttpOnly;
35-
}
33+
add_header Set-Cookie "session_id=$cookie_session_id; SameSite=Strict; Secure; HttpOnly; Path=/";
3634
spec:
3735
ingressClassName: "nginx-control-plane"
3836
rules:

0 commit comments

Comments
 (0)