Skip to content

Use SameSite cookies for auth #284

@sergeychernyshev

Description

@sergeychernyshev

Use SameSite (first party) cookies for authentication unless specifically turned off for API or other types of integrations.

Support is currently around 57% so it can't be a measure to rely on, but can be an additional security measure: https://caniuse.com/#search=same-site

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions