Skip to content

Commit 0600f79

Browse files
authored
Add missing SameSite settings for the i_like_gitea cookie (#16037) (#16039)
Backport #16037 The i_like_gitea cookie appears to be missing the SameSite settings. I think they were present at some point but may have been removed in a merge. This PR ensures that they are set. Fix #15972 Signed-off-by: Andrew Thornton <[email protected]>
1 parent 8007602 commit 0600f79

File tree

3 files changed

+3
-0
lines changed

3 files changed

+3
-0
lines changed

routers/api/v1/api.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -557,6 +557,7 @@ func Routes() *web.Route {
557557
Gclifetime: setting.SessionConfig.Gclifetime,
558558
Maxlifetime: setting.SessionConfig.Maxlifetime,
559559
Secure: setting.SessionConfig.Secure,
560+
SameSite: setting.SessionConfig.SameSite,
560561
Domain: setting.SessionConfig.Domain,
561562
}))
562563
m.Use(securityHeaders())

routers/routes/install.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -89,6 +89,7 @@ func InstallRoutes() *web.Route {
8989
Gclifetime: setting.SessionConfig.Gclifetime,
9090
Maxlifetime: setting.SessionConfig.Maxlifetime,
9191
Secure: setting.SessionConfig.Secure,
92+
SameSite: setting.SessionConfig.SameSite,
9293
Domain: setting.SessionConfig.Domain,
9394
}))
9495

routers/routes/web.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -135,6 +135,7 @@ func WebRoutes() *web.Route {
135135
Gclifetime: setting.SessionConfig.Gclifetime,
136136
Maxlifetime: setting.SessionConfig.Maxlifetime,
137137
Secure: setting.SessionConfig.Secure,
138+
SameSite: setting.SessionConfig.SameSite,
138139
Domain: setting.SessionConfig.Domain,
139140
}))
140141

0 commit comments

Comments
 (0)