mirror of
https://github.com/miniflux/v2.git
synced 2025-08-06 17:41:00 +00:00
feat(cookie): use SameSiteStrictMode
when not using OAuth2/OIDC
This commit is contained in:
parent
abed7b11ce
commit
135ce1d546
1 changed files with 16 additions and 4 deletions
|
@ -18,20 +18,26 @@ const (
|
||||||
|
|
||||||
// New creates a new cookie.
|
// New creates a new cookie.
|
||||||
func New(name, value string, isHTTPS bool, path string) *http.Cookie {
|
func New(name, value string, isHTTPS bool, path string) *http.Cookie {
|
||||||
return &http.Cookie{
|
cookie := &http.Cookie{
|
||||||
Name: name,
|
Name: name,
|
||||||
Value: value,
|
Value: value,
|
||||||
Path: basePath(path),
|
Path: basePath(path),
|
||||||
Secure: isHTTPS,
|
Secure: isHTTPS,
|
||||||
HttpOnly: true,
|
HttpOnly: true,
|
||||||
Expires: time.Now().Add(time.Duration(config.Opts.CleanupRemoveSessionsDays()) * 24 * time.Hour),
|
Expires: time.Now().Add(time.Duration(config.Opts.CleanupRemoveSessionsDays()) * 24 * time.Hour),
|
||||||
SameSite: http.SameSiteLaxMode,
|
SameSite: http.SameSiteStrictMode,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// OAuth doesn't work when cookies are in strict mode.
|
||||||
|
if config.Opts.OAuth2Provider() != "" {
|
||||||
|
cookie.SameSite = http.SameSiteLaxMode
|
||||||
|
}
|
||||||
|
return cookie
|
||||||
}
|
}
|
||||||
|
|
||||||
// Expired returns an expired cookie.
|
// Expired returns an expired cookie.
|
||||||
func Expired(name string, isHTTPS bool, path string) *http.Cookie {
|
func Expired(name string, isHTTPS bool, path string) *http.Cookie {
|
||||||
return &http.Cookie{
|
cookie := &http.Cookie{
|
||||||
Name: name,
|
Name: name,
|
||||||
Value: "",
|
Value: "",
|
||||||
Path: basePath(path),
|
Path: basePath(path),
|
||||||
|
@ -39,8 +45,14 @@ func Expired(name string, isHTTPS bool, path string) *http.Cookie {
|
||||||
HttpOnly: true,
|
HttpOnly: true,
|
||||||
MaxAge: -1,
|
MaxAge: -1,
|
||||||
Expires: time.Date(1970, 1, 1, 0, 0, 0, 0, time.UTC),
|
Expires: time.Date(1970, 1, 1, 0, 0, 0, 0, time.UTC),
|
||||||
SameSite: http.SameSiteLaxMode,
|
SameSite: http.SameSiteStrictMode,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// OAuth doesn't work when cookies are in strict mode.
|
||||||
|
if config.Opts.OAuth2Provider() != "" {
|
||||||
|
cookie.SameSite = http.SameSiteLaxMode
|
||||||
|
}
|
||||||
|
return cookie
|
||||||
}
|
}
|
||||||
|
|
||||||
func basePath(path string) string {
|
func basePath(path string) string {
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue