1
0
mirror of https://github.com/meineerde/redmine.git synced 2026-01-31 11:37:14 +00:00

Add SameSite=Lax to cookies to fix warnings in web browsers (#35226).

Patch by Go MAEDA.


git-svn-id: http://svn.redmine.org/redmine/trunk@21009 e93f8b46-1217-0410-a6f0-8f06a7374b81
This commit is contained in:
Go MAEDA 2021-05-27 08:31:15 +00:00
parent 8b8a1194ff
commit 099b160d11
3 changed files with 4 additions and 2 deletions

View File

@ -404,6 +404,7 @@ class AccountController < ApplicationController
:value => token,
:expires => 1.year.from_now,
:path => (Redmine::Configuration['autologin_cookie_path'] || RedmineApp::Application.config.relative_url_root || '/'),
:same_site => :lax,
:secure => secure,
:httponly => true
}

View File

@ -79,7 +79,8 @@ module RedmineApp
config.session_store(
:cookie_store,
:key => '_redmine_session',
:path => config.relative_url_root || '/'
:path => config.relative_url_root || '/',
:same_site => :lax
)
if File.exists?(File.join(File.dirname(__FILE__), 'additional_environment.rb'))

View File

@ -1033,7 +1033,7 @@ $(document).ready(function(){
$('#history .tabs').on('click', 'a', function(e){
var tab = $(e.target).attr('id').replace('tab-','');
document.cookie = 'history_last_tab=' + tab
document.cookie = 'history_last_tab=' + tab + '; SameSite=Lax'
});
});