Add support for SamSite cookie attribute #1376
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This pull request adds support for the SameSite cookie attribute to:
It also adds tests for the added functionality via:
According to the description of SameSite cookies on MDN [1] the SameSite cookie attribute controls in requests a cookie is included in.
The absence of the SameSite attribute might trigger warnings in modern browsers.
Some browsers might event reject cookies with missing or wrongly set SameSite attributes.
Some scenarios might also require the SameSite attribute to be
Strict
so the corresponding cookie is only being sent in requests initiated by the same site.The changes in
modules/org.restlet.test/pom.xml
where necessary for eclipse to match the packages with the folder structure.[1] - https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite