From d63de5471bf3c8a40bdc9f9e3b5332d2f0b1f2a9 Mon Sep 17 00:00:00 2001 From: Thomas Citharel Date: Wed, 17 Oct 2018 09:24:21 +0200 Subject: Don't require Same Site Cookies on assets Which can be used for public iframe embeeding See https://github.com/nextcloud/calendar/issues/169 Signed-off-by: Thomas Citharel --- core/Controller/CssController.php | 1 + core/Controller/JsController.php | 1 + core/Controller/SvgController.php | 2 ++ 3 files changed, 4 insertions(+) (limited to 'core') diff --git a/core/Controller/CssController.php b/core/Controller/CssController.php index c8458eab29c..901074d0285 100644 --- a/core/Controller/CssController.php +++ b/core/Controller/CssController.php @@ -62,6 +62,7 @@ class CssController extends Controller { /** * @PublicPage * @NoCSRFRequired + * @NoSameSiteCookieRequired * * @param string $fileName css filename with extension * @param string $appName css folder name diff --git a/core/Controller/JsController.php b/core/Controller/JsController.php index f91fe8f75d5..cdf22eda5fa 100644 --- a/core/Controller/JsController.php +++ b/core/Controller/JsController.php @@ -56,6 +56,7 @@ class JsController extends Controller { /** * @PublicPage * @NoCSRFRequired + * @NoSameSiteCookieRequired * * @param string $fileName js filename with extension * @param string $appName js folder name diff --git a/core/Controller/SvgController.php b/core/Controller/SvgController.php index c6bf7b94da3..f7159dd9fe1 100644 --- a/core/Controller/SvgController.php +++ b/core/Controller/SvgController.php @@ -57,6 +57,7 @@ class SvgController extends Controller { /** * @PublicPage * @NoCSRFRequired + * @NoSameSiteCookieRequired * * Generate svg from filename with the requested color * @@ -73,6 +74,7 @@ class SvgController extends Controller { /** * @PublicPage * @NoCSRFRequired + * @NoSameSiteCookieRequired * * Generate svg from filename with the requested color * -- cgit v1.2.3