SameSite cookie in Java application

后端 未结 9 2041
没有蜡笔的小新
没有蜡笔的小新 2020-12-24 01:08

Do you know any Java cookie implementation which allows to set a custom flag for cookie, like SameSite=strict? It seems that javax.servlet.http.Cookie has a str

9条回答
  •  不知归路
    2020-12-24 01:31

    I found that our cookies which were being created on a successful return were not changed by "Header edit" or "Header always edit". Apparently apache has two buckets of cookies - see this

    What did work for me was

    Header onsuccess edit Set-Cookie (.*) "$1; SameSite=Lax"
    

提交回复
热议问题