Selaa lähdekoodia

Add missing SameSite settings for the i_like_gitea cookie (#16037) (#16039)

Backport #16037

The i_like_gitea cookie appears to be missing the SameSite settings. I think they
were present at some point but may have been removed in a merge.

This PR ensures that they are set.

Fix #15972

Signed-off-by: Andrew Thornton <art27@cantab.net>
tags/v1.14.3
zeripath 3 vuotta sitten
vanhempi
commit
0600f7972a
No account linked to committer's email address
3 muutettua tiedostoa jossa 3 lisäystä ja 0 poistoa
  1. 1
    0
      routers/api/v1/api.go
  2. 1
    0
      routers/routes/install.go
  3. 1
    0
      routers/routes/web.go

+ 1
- 0
routers/api/v1/api.go Näytä tiedosto

@@ -557,6 +557,7 @@ func Routes() *web.Route {
Gclifetime: setting.SessionConfig.Gclifetime,
Maxlifetime: setting.SessionConfig.Maxlifetime,
Secure: setting.SessionConfig.Secure,
SameSite: setting.SessionConfig.SameSite,
Domain: setting.SessionConfig.Domain,
}))
m.Use(securityHeaders())

+ 1
- 0
routers/routes/install.go Näytä tiedosto

@@ -89,6 +89,7 @@ func InstallRoutes() *web.Route {
Gclifetime: setting.SessionConfig.Gclifetime,
Maxlifetime: setting.SessionConfig.Maxlifetime,
Secure: setting.SessionConfig.Secure,
SameSite: setting.SessionConfig.SameSite,
Domain: setting.SessionConfig.Domain,
}))


+ 1
- 0
routers/routes/web.go Näytä tiedosto

@@ -135,6 +135,7 @@ func WebRoutes() *web.Route {
Gclifetime: setting.SessionConfig.Gclifetime,
Maxlifetime: setting.SessionConfig.Maxlifetime,
Secure: setting.SessionConfig.Secure,
SameSite: setting.SessionConfig.SameSite,
Domain: setting.SessionConfig.Domain,
}))


Loading…
Peruuta
Tallenna