Skip to content

Set session cookie to default to secure and set samesite to strict#162

Merged
Phocacius merged 2 commits intomasterfrom
work/cookie-secure
Mar 18, 2026
Merged

Set session cookie to default to secure and set samesite to strict#162
Phocacius merged 2 commits intomasterfrom
work/cookie-secure

Conversation

@Phocacius
Copy link
Member

@Phocacius Phocacius commented Feb 16, 2026

  • Set default session handling to use file storage for more reliable session durations. This can be changed back by setting framework.session.handler_id to null in config/packages/framework.yaml
  • set session cookie to default to secure and set samesite to strict

@Phocacius Phocacius requested a review from astroidex February 16, 2026 20:36
@astroidex astroidex added this to the 4.2.5 milestone Feb 18, 2026
@Phocacius Phocacius merged commit e58c4e6 into master Mar 18, 2026
@Phocacius Phocacius deleted the work/cookie-secure branch March 18, 2026 09:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants