Skip to content

fix: secure='auto' and sameSite='none' case - #817

Closed
simllll wants to merge 1 commit into
expressjs:masterfrom
simllll:patch-1
Closed

fix: secure='auto' and sameSite='none' case#817
simllll wants to merge 1 commit into
expressjs:masterfrom
simllll:patch-1

Conversation

@simllll

@simllll simllll commented Feb 26, 2021

Copy link
Copy Markdown

if secure is set to auto and sameSite is set to none it can result into secure is set to false, and therefore the cookie will not be set.
Because sameSite none always needs a secure context.

This fixes this behaviour, in case secure evaluates to false and sameSite is set explicitly to none, sameSite will be removed.

related to #778

if secure is set to `auto` and sameSite is set to `none` it can result into secure is set to false, and therefore the cookie will not be set.
Because sameSite none always needs a secure context.

This fixes this behaviour, in case secure evaluates to false and sameSite is set explicitly to none, sameSite will be removed.
@simllll simllll changed the title fix: secure aut and samesite none case fix: secure auto and samesite none case Feb 26, 2021
@simllll simllll changed the title fix: secure auto and samesite none case fix: secure='auto' and samesite='none' case Feb 26, 2021
@simllll simllll changed the title fix: secure='auto' and samesite='none' case fix: secure='auto' and sameSite='none' case Feb 26, 2021
@dougwilson

Copy link
Copy Markdown
Contributor

See discussion in #725

@simllll

simllll commented Feb 26, 2021

Copy link
Copy Markdown
Author

Sorry i missed that, still don't really follow the reasoning because secure has a auto flag, why samesite shouldn't benefit from that too... ;) But when I find time i will add a comment on the other thread. Thanks for pointing me to it :)!

@dougwilson

Copy link
Copy Markdown
Contributor

The issue is these two settings control completely different behaviors. Beaides that, if you need a samesite none cookie, how can your aite possibly work when the cookie is now lax or strict? It would reason that if you site does indees work with a strict or lax cookie, that is what you should be using and not none.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants