csrf

  1. ⭐ Alex ⭐

    XF 2.2 Is There Still a Reason to Not Use SameSite Strict or Lax for Cookies?

    I've put $config['cookie']['samesite'] = 'Strict'; into my config.php, deleted my cookies and verified their SameSite attribute are set to Strict. Then I tried accessing my forum from a link on social media. I also tried registering using a social media account and logging in. Everything...
Top Bottom