You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Sep 10, 2024. It is now read-only.
I think localhost is considered 'Secure' so this shouldn't affect local development much, but there is a minor possibility this would need to be configurable.
The text was updated successfully, but these errors were encountered:
I was just looking at the code for the CSRF token cookie and suspect it could be improved.
matrix-authentication-service/crates/axum-utils/src/csrf.rs
Line 134 in 7c67630
__Host-
to prevent, in modern browsers that support this, some classes of cookie fixation attacks.https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies
I think localhost is considered 'Secure' so this shouldn't affect local development much, but there is a minor possibility this would need to be configurable.
The text was updated successfully, but these errors were encountered: