-
Notifications
You must be signed in to change notification settings - Fork 454
Closed
Description
As of 2021-01, Firefox 84 warns when hosting isso on a subdomain and accessing cookies.
Repro:
- Isso hosted at
comments.example.com - "Blog" hosted at
example.com
Warning:
Cookie “isso-[id]” will be soon rejected because it has the “SameSite” attribute set to “None”. [...]
with a link to MDM SameSite cookies.
Cause:
In isso/views/comments.py, e.g. new() creates a new cookie with SameSite implicitly set to False and Secure implicitly set to None1.
Possible solutions
- Isso sets
Securecookie by default. Big problem is that large parts of isso assume that it might be accessed overhttp, see e.g. the default isso.conf - Isso conditionally sets
Securecookie only forhttpshosts. Ugly but doable.
Help wanted
Would be great if someone who's more involved with web technology could step in and give their ideas and clarify whether my understanding here is even correct.
Footnotes
-
For the full call chain, see the later X-Set-Cookie and the defaults of
werkzeug's http.dump_cookie ↩
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels