Recent content by Fozzie

  1. F

    XF 2.1 SameSite cookies and removal of anti-CSRF tokens

    Thanks for the reply, but if all cookies are set with SameSite to Lax what is the point of the anti-CSRF token? Can you at least give us an option to remove it?
  2. F

    XF 2.1 SameSite cookies and removal of anti-CSRF tokens

    Why aren't the xf_user and xf_session cookies set to SameSite Lax? Assuming all forms are using POST then authentication cookies with the SameSite Lax value will not be sent for cross origin requests, eliminating the need for any anti-CSRF tokens at all. Both Chrome and Firefox now...
Top Bottom