summaryrefslogtreecommitdiffstats
path: root/core/Controller
diff options
context:
space:
mode:
authorThomas Citharel <tcit@tcit.fr>2018-10-17 09:24:21 +0200
committerThomas Citharel <tcit@tcit.fr>2018-10-17 09:24:21 +0200
commitd63de5471bf3c8a40bdc9f9e3b5332d2f0b1f2a9 (patch)
treec421fdbfea6d09612fd6b6d7806a00d89a33e284 /core/Controller
parentb88ab75c3a09c6e275735b0bf14108f8add72e5d (diff)
downloadnextcloud-server-d63de5471bf3c8a40bdc9f9e3b5332d2f0b1f2a9.tar.gz
nextcloud-server-d63de5471bf3c8a40bdc9f9e3b5332d2f0b1f2a9.zip
Don't require Same Site Cookies on assets
Which can be used for public iframe embeeding See https://github.com/nextcloud/calendar/issues/169 Signed-off-by: Thomas Citharel <tcit@tcit.fr>
Diffstat (limited to 'core/Controller')
-rw-r--r--core/Controller/CssController.php1
-rw-r--r--core/Controller/JsController.php1
-rw-r--r--core/Controller/SvgController.php2
3 files changed, 4 insertions, 0 deletions
diff --git a/core/Controller/CssController.php b/core/Controller/CssController.php
index c8458eab29c..901074d0285 100644
--- a/core/Controller/CssController.php
+++ b/core/Controller/CssController.php
@@ -62,6 +62,7 @@ class CssController extends Controller {
/**
* @PublicPage
* @NoCSRFRequired
+ * @NoSameSiteCookieRequired
*
* @param string $fileName css filename with extension
* @param string $appName css folder name
diff --git a/core/Controller/JsController.php b/core/Controller/JsController.php
index f91fe8f75d5..cdf22eda5fa 100644
--- a/core/Controller/JsController.php
+++ b/core/Controller/JsController.php
@@ -56,6 +56,7 @@ class JsController extends Controller {
/**
* @PublicPage
* @NoCSRFRequired
+ * @NoSameSiteCookieRequired
*
* @param string $fileName js filename with extension
* @param string $appName js folder name
diff --git a/core/Controller/SvgController.php b/core/Controller/SvgController.php
index c6bf7b94da3..f7159dd9fe1 100644
--- a/core/Controller/SvgController.php
+++ b/core/Controller/SvgController.php
@@ -57,6 +57,7 @@ class SvgController extends Controller {
/**
* @PublicPage
* @NoCSRFRequired
+ * @NoSameSiteCookieRequired
*
* Generate svg from filename with the requested color
*
@@ -73,6 +74,7 @@ class SvgController extends Controller {
/**
* @PublicPage
* @NoCSRFRequired
+ * @NoSameSiteCookieRequired
*
* Generate svg from filename with the requested color
*