Skip to content

v0.0.2

@slayercat slayercat tagged this 26 Dec 07:28
SameSite cookie is used to prevent CSRF attack.It is supported by modern browsers and in RFC draft.

REFS:
   RFC draft: https://tools.ietf.org/html/draft-west-first-party-cookies-07
   upstream support:  [golang](https://godoc.org/net/http#SameSite)
                      [gorilla/sessions](https://godoc.org/github.com/gorilla/sessions#Options)
   supports of browser: https://caniuse.com/#feat=same-site-cookie-attribute

Signed-off-by: lilinzhe <slayercat.subscription@gmail.com>
Assets 2
Loading