Consider adding None
to the list of values for the SameSite
attribute.
#788
Labels
None
to the list of values for the SameSite
attribute.
#788
Giving developers an explicit keyword that asserts non-
SameSite
ness seems like it's both helpful from an explanatory perspective, and could open paths towards tightening cookie behavior in the future. Perhaps something likeSameSite=None
to represent the status quo default behavior. That is, the following twoSet-Cookie
header values would produce the same cookie today:The text was updated successfully, but these errors were encountered: