From 6f07f63960fc48934e935a8e84b897685c8b9b6e Mon Sep 17 00:00:00 2001 From: Sean Yesmunt Date: Tue, 7 Apr 2020 18:25:40 -0400 Subject: [PATCH] use SameSite=None for auth_token cookie --- ui/util/saved-passwords.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ui/util/saved-passwords.js b/ui/util/saved-passwords.js index a096293a2..0b3b70861 100644 --- a/ui/util/saved-passwords.js +++ b/ui/util/saved-passwords.js @@ -16,7 +16,7 @@ function setCookie(name, value, expirationDaysOnWeb) { expires = `expires=${IS_WEB ? date.toUTCString() : maxExpiration};`; } - let cookie = `${name}=${value || ''}; ${expires} path=/; SameSite=Lax;`; + let cookie = `${name}=${value || ''}; ${expires} path=/; SameSite=None;`; if (isProduction) { cookie += ` domain=${domain}; Secure;`; }