Branch: refs/heads/master
Home:
https://github.com/tribe29/checkmk
Commit: 960c4f3680140964c41cdc0a889d4184eebb00f7
https://github.com/tribe29/checkmk/commit/960c4f3680140964c41cdc0a889d4184e…
Author: Lars Michelsen <lm(a)tribe29.com>
Date: 2020-09-16 (Wed, 16 Sep 2020)
Changed paths:
A .werks/11492
Log Message:
-----------
11491 SEC Auth cookies: Specify SameSite attribute to improve cookie security
The authentication cookies of the Checkmk GUI (auth_[site]) previously relied
on the browsers default behaviour regarding the same site policy. This resulted
in a) an inconsistent cookie handling across the different browsers and b)
allow some sort of Cross-site request forgery (CSRF) attacks.
With this change we explicitly set the "SameSite=Lax" setting for all
authentication cookies created by logins after updating Checkmk.
For more information about this HTTP cookie setting have a look at
https://web.dev/samesite-cookies-explained/.
Change-Id: I42fd2d654f8364b6b90233f5aac9c71180b903d9