Skip to content
Unverified Commit 9a7265ba authored by Roeland Jago Douma's avatar Roeland Jago Douma
Browse files

Make authenticated cookies lax



This protects our cookies a bit more. It makes sure that when a 3rdparty
websites embededs a public alendar for example. That all the users see
this in anonymous mode there.

It adds a small helper function.

In the future we can think about protecting other cookies like this as
well. But for now this is sufficient to not have the user logged in at
all when doing 3rdparty requests.

Signed-off-by: default avatarRoeland Jago Douma <roeland@famdouma.nl>
parent db50e11e
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment