[Koha-bugs] [Bug 26019] Koha should set SameSite attribute on cookies

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Thu Aug 6 14:38:59 CEST 2020


https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=26019

--- Comment #5 from Tomás Cohen Arazi <tomascohen at gmail.com> ---
(In reply to David Cook from comment #3)
> (In reply to Marcel de Rooy from comment #2)
> > Why wouldnt we add a preference like SameSiteCookie to include cookie names
> > that do not want to default to Lax ?
> 
> Why should we let librarians determine cookie settings? It seems to me that
> we as developers are best suited to making those choices?

I think we should provide a sane default, and probably have a separate tab for
'Risky area'.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are watching all bug changes.


More information about the Koha-bugs mailing list