aboutsummaryrefslogtreecommitdiffhomepage
path: root/http
diff options
context:
space:
mode:
authorGravatar Frédéric Guillot <fred@miniflux.net>2018-08-29 21:09:42 -0700
committerGravatar Frédéric Guillot <fred@miniflux.net>2018-08-29 21:17:19 -0700
commit88e81d4d800ff6433518522954197d75203a25c2 (patch)
treeeea49d25be330018eec93100cffebc8c5afe97ff /http
parent6137b401eec5a96101a6acb3c3547e7269d7eeb6 (diff)
Set cookie attribute SameSite to strict mode
Diffstat (limited to 'http')
-rw-r--r--http/cookie/cookie.go2
1 files changed, 2 insertions, 0 deletions
diff --git a/http/cookie/cookie.go b/http/cookie/cookie.go
index d0e55eb..9ac79a1 100644
--- a/http/cookie/cookie.go
+++ b/http/cookie/cookie.go
@@ -27,6 +27,7 @@ func New(name, value string, isHTTPS bool, path string) *http.Cookie {
Secure: isHTTPS,
HttpOnly: true,
Expires: time.Now().Add(cookieDuration * 24 * time.Hour),
+ SameSite: http.SameSiteStrictMode,
}
}
@@ -40,6 +41,7 @@ func Expired(name string, isHTTPS bool, path string) *http.Cookie {
HttpOnly: true,
MaxAge: -1,
Expires: time.Date(1970, 1, 1, 0, 0, 0, 0, time.UTC),
+ SameSite: http.SameSiteStrictMode,
}
}