use SameSite=None for auth_token cookie

This commit is contained in:
Sean Yesmunt 2020-04-07 18:25:40 -04:00
parent 39102d81ca
commit 6f07f63960

View file

@ -16,7 +16,7 @@ function setCookie(name, value, expirationDaysOnWeb) {
expires = `expires=${IS_WEB ? date.toUTCString() : maxExpiration};`;
}
let cookie = `${name}=${value || ''}; ${expires} path=/; SameSite=Lax;`;
let cookie = `${name}=${value || ''}; ${expires} path=/; SameSite=None;`;
if (isProduction) {
cookie += ` domain=${domain}; Secure;`;
}