From efca48ee96cb6b91a8ececa9774efe343829bf6f Mon Sep 17 00:00:00 2001 From: evazion Date: Mon, 9 Sep 2019 11:51:01 -0500 Subject: [PATCH] Set SameSite=Lax on session cookies. https://web.dev/samesite-cookies-explained --- config/initializers/session_store.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/initializers/session_store.rb b/config/initializers/session_store.rb index eae602d8d..4d686690f 100644 --- a/config/initializers/session_store.rb +++ b/config/initializers/session_store.rb @@ -1,3 +1,3 @@ # Be sure to restart your server when you modify this file. -Rails.application.config.session_store :cookie_store, key: '_danbooru2_session', domain: :all, tld_length: 2 +Rails.application.config.session_store :cookie_store, key: '_danbooru2_session', domain: :all, tld_length: 2, same_site: :lax