From 044ed4a9347c9ab944f826f98996694499e85ee8 Mon Sep 17 00:00:00 2001 From: Robert Newson Date: Thu, 9 Dec 2021 19:17:59 +0000 Subject: Add SameSite setting when clearing session cookie (2) I missed a case. --- src/couch/src/couch_httpd_auth.erl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/couch/src/couch_httpd_auth.erl b/src/couch/src/couch_httpd_auth.erl index ed6b1e604..5bf0c24e1 100644 --- a/src/couch/src/couch_httpd_auth.erl +++ b/src/couch/src/couch_httpd_auth.erl @@ -486,7 +486,7 @@ handle_session_req(#httpd{method = 'POST', mochi_req = MochiReq} = Req, AuthModu authentication_warning(Req, UserName), % clear the session Cookie = mochiweb_cookies:cookie( - "AuthSession", "", [{path, "/"}] ++ cookie_scheme(Req) + "AuthSession", "", [{path, "/"}] ++ cookie_scheme(Req) ++ same_site() ), {Code, Headers} = case couch_httpd:qs_value(Req, "fail", nil) of -- cgit v1.2.1