Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
François
@fkooman@floss.social  ·  activity timestamp last month

After reading (and implementing) "Protecting against CSRF in 2025" (see link below), I'm wondering now whether cookies should still have any SameSite attribute at all, or whether it would be better to completely drop it and keep whatever is the browser's default for (session) cookies handling?

https://words.filippo.io/csrf/

#web #security #cookies #csrf

  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.2.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login