From 5ac55518abe87ff871942c02c0cf0c536c6035d8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fr=C3=A9d=C3=A9ric=20Guillot?= Date: Wed, 5 Aug 2020 21:19:02 -0700 Subject: [PATCH] Set SameSite cookie attribute to Strict --- http/cookie/cookie.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/http/cookie/cookie.go b/http/cookie/cookie.go index 8874c412..74f95314 100644 --- a/http/cookie/cookie.go +++ b/http/cookie/cookie.go @@ -27,7 +27,7 @@ func New(name, value string, isHTTPS bool, path string) *http.Cookie { Secure: isHTTPS, HttpOnly: true, Expires: time.Now().Add(cookieDuration * 24 * time.Hour), - SameSite: http.SameSiteLaxMode, + SameSite: http.SameSiteStrictMode, } } @@ -41,7 +41,7 @@ func Expired(name string, isHTTPS bool, path string) *http.Cookie { HttpOnly: true, MaxAge: -1, Expires: time.Date(1970, 1, 1, 0, 0, 0, 0, time.UTC), - SameSite: http.SameSiteLaxMode, + SameSite: http.SameSiteStrictMode, } }