]> cat aescling's git repositories - mastodon.git/commitdiff
Disable Same-Site cookie implementation to fix SSO issues on WebKit browsers (#9819)
authorMoritz Heiber <github@heiber.im>
Tue, 15 Jan 2019 22:11:46 +0000 (23:11 +0100)
committerEugen Rochko <eugen@zeonfederated.com>
Tue, 15 Jan 2019 22:11:46 +0000 (23:11 +0100)
config/initializers/devise.rb
config/initializers/session_store.rb
spec/rails_helper.rb

index 3e4c9a79d7afad792bda0ca917d6a14d967c0de1..cd9bacf68033e609abf0e662b9958b8b00555499 100644 (file)
@@ -10,7 +10,6 @@ Warden::Manager.after_set_user except: :fetch do |user, warden|
     expires: 1.year.from_now,
     httponly: true,
     secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true'),
-    same_site: :lax,
   }
 end
 
@@ -21,7 +20,6 @@ Warden::Manager.after_fetch do |user, warden|
       expires: 1.year.from_now,
       httponly: true,
       secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true'),
-      same_site: :lax,
     }
   else
     warden.logout
index c0757b6b5730915f1178ca3e7ef512b1fb1bc9b8..3dc0edd6fd262f70a6c496c922beb97bd096003c 100644 (file)
@@ -1,3 +1,3 @@
 # Be sure to restart your server when you modify this file.
 
-Rails.application.config.session_store :cookie_store, key: '_mastodon_session', secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true'), same_site: :lax
+Rails.application.config.session_store :cookie_store, key: '_mastodon_session', secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true')
index 1ded751ab73cd6ef09d3de964c73d86c5530d3ac..3a5e7491e515198888d2bc25733fab67fbec2a97 100644 (file)
@@ -29,7 +29,6 @@ Devise::Test::ControllerHelpers.module_eval do
       value: resource.activate_session(warden.request),
       expires: 1.year.from_now,
       httponly: true,
-      same_site: :lax,
     }
   end
 end