From c00cce3229515eacdb1680f39132ed3ca09cc205 Mon Sep 17 00:00:00 2001 From: Nikita Popov Date: Wed, 18 Mar 2020 15:59:30 +0100 Subject: Clarify session.cookie_samesite="None" --- php.ini-development | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'php.ini-development') diff --git a/php.ini-development b/php.ini-development index c365201809..b8ed4fb094 100644 --- a/php.ini-development +++ b/php.ini-development @@ -1413,7 +1413,8 @@ session.cookie_domain = session.cookie_httponly = ; Add SameSite attribute to cookie to help mitigate Cross-Site Request Forgery (CSRF/XSRF) -; Current valid values are "Lax" or "Strict" +; Current valid values are "Strict", "Lax" or "None". When using "None", +; make sure to include the quotes, as `none` is interpreted like `false` in ini files. ; https://tools.ietf.org/html/draft-west-first-party-cookies-07 session.cookie_samesite = -- cgit v1.2.1