Skip to content

Commit

Permalink
Set SameSite directive for auth_token cookie
Browse files Browse the repository at this point in the history
  • Loading branch information
kdp-cloud committed Jan 22, 2025
1 parent 3346780 commit 35acf70
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion app/controllers/sessions_controller.rb
Original file line number Diff line number Diff line change
Expand Up @@ -99,7 +99,7 @@ def successful_login(notice = nil)
flash[:notice] = notice || "You have successfully logged in, #{@user.display_name}."
if params[:remember_me] == 'on'
@user.remember_me unless @user.remember_token?
cookies[:auth_token] = { value: @user.remember_token, expires: @user.remember_token_expires_at }
cookies[:auth_token] = { value: @user.remember_token, expires: @user.remember_token_expires_at, same_site: :strict }
end
respond_to do |format|
return_to_path = determine_return_path_after_login
Expand Down

0 comments on commit 35acf70

Please sign in to comment.