Changed default policy from 'strict' to 'lax' due to the reasons mentioned in 3d1fab05

Signed-off-by: Erik Michelson <github@erik.michelson.eu>
This commit is contained in:
Erik Michelson 2020-08-27 09:05:17 +02:00
parent 824f910bfe
commit 387e668275
No known key found for this signature in database
GPG key ID: DB99ADDDC5C0AF82
2 changed files with 2 additions and 2 deletions

View file

@ -27,7 +27,7 @@ module.exports = {
upgradeInsecureRequests: 'auto', upgradeInsecureRequests: 'auto',
reportURI: undefined reportURI: undefined
}, },
cookiePolicy: 'strict', cookiePolicy: 'lax',
protocolUseSSL: false, protocolUseSSL: false,
useCDN: false, useCDN: false,
allowAnonymous: true, allowAnonymous: true,

View file

@ -53,7 +53,7 @@ if (['debug', 'verbose', 'info', 'warn', 'error'].includes(config.loglevel)) {
if (!['strict', 'lax', 'none'].includes(config.cookiePolicy)) { if (!['strict', 'lax', 'none'].includes(config.cookiePolicy)) {
logger.error('Cookie SameSite policy %s does not exist. Falling back to strict. Available values are: strict, lax, none.', config.cookiePolicy) logger.error('Cookie SameSite policy %s does not exist. Falling back to strict. Available values are: strict, lax, none.', config.cookiePolicy)
config.cookiePolicy = 'strict' config.cookiePolicy = 'lax'
} }
// load LDAP CA // load LDAP CA