Skip to content
This repository was archived by the owner on Nov 22, 2018. It is now read-only.

Conversation

@JunTaoLuo
Copy link
Contributor

Reacting to aspnet/HttpAbstractions#843. We would like to keep the default as None since sessions may be used in cross-site requests (via redirects).

@JunTaoLuo
Copy link
Contributor Author

Updated the default to Lax. Users can set the option to None if they require cross-site unsafe requests.

@JunTaoLuo JunTaoLuo merged commit b899775 into dev May 31, 2017
@JunTaoLuo JunTaoLuo deleted the johluo/samesite branch May 31, 2017 22:49
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

4 participants