fix: Allow loading attachments linked from other sites/emails.
Loosens same-site policy to include cookies for navigation events. closes #4737
This commit is contained in:
@@ -34,7 +34,7 @@ router.get("/redirect", auth(), async (ctx: APIContext) => {
|
|||||||
|
|
||||||
ctx.cookies.set("accessToken", jwtToken, {
|
ctx.cookies.set("accessToken", jwtToken, {
|
||||||
httpOnly: false,
|
httpOnly: false,
|
||||||
sameSite: true,
|
sameSite: "lax",
|
||||||
expires: addMonths(new Date(), 3),
|
expires: addMonths(new Date(), 3),
|
||||||
});
|
});
|
||||||
const [team, collection, view] = await Promise.all([
|
const [team, collection, view] = await Promise.all([
|
||||||
|
|||||||
@@ -119,7 +119,7 @@ export async function signIn(
|
|||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
ctx.cookies.set("accessToken", user.getJwtToken(), {
|
ctx.cookies.set("accessToken", user.getJwtToken(), {
|
||||||
sameSite: true,
|
sameSite: "lax",
|
||||||
httpOnly: false,
|
httpOnly: false,
|
||||||
expires,
|
expires,
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user