about summary refs log tree commit diff
path: root/config/initializers
diff options
context:
space:
mode:
authorMoritz Heiber <github@heiber.im>2019-01-15 23:11:46 +0100
committerEugen Rochko <eugen@zeonfederated.com>2019-01-15 23:11:46 +0100
commitecf40d09ed42c15f1379718d70142434a72986f5 (patch)
tree63e5b08203847f3651d5ecde86e3cf4e8290255e /config/initializers
parenta12f6d10cc747073b612c3d2bcf66719e9754297 (diff)
Disable Same-Site cookie implementation to fix SSO issues on WebKit browsers (#9819)
Diffstat (limited to 'config/initializers')
-rw-r--r--config/initializers/devise.rb2
-rw-r--r--config/initializers/session_store.rb2
2 files changed, 1 insertions, 3 deletions
diff --git a/config/initializers/devise.rb b/config/initializers/devise.rb
index 3e4c9a79d..cd9bacf68 100644
--- a/config/initializers/devise.rb
+++ b/config/initializers/devise.rb
@@ -10,7 +10,6 @@ Warden::Manager.after_set_user except: :fetch do |user, warden|
     expires: 1.year.from_now,
     httponly: true,
     secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true'),
-    same_site: :lax,
   }
 end
 
@@ -21,7 +20,6 @@ Warden::Manager.after_fetch do |user, warden|
       expires: 1.year.from_now,
       httponly: true,
       secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true'),
-      same_site: :lax,
     }
   else
     warden.logout
diff --git a/config/initializers/session_store.rb b/config/initializers/session_store.rb
index c0757b6b5..3dc0edd6f 100644
--- a/config/initializers/session_store.rb
+++ b/config/initializers/session_store.rb
@@ -1,3 +1,3 @@
 # Be sure to restart your server when you modify this file.
 
-Rails.application.config.session_store :cookie_store, key: '_mastodon_session', secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true'), same_site: :lax
+Rails.application.config.session_store :cookie_store, key: '_mastodon_session', secure: (Rails.env.production? || ENV['LOCAL_HTTPS'] == 'true')