[pgAdmin4] To make session cookie more secure (Server mode) - Mailing list pgadmin-hackers

From Murtuza Zabuawala
Subject [pgAdmin4] To make session cookie more secure (Server mode)
Date
Msg-id CAKKotZRrRNhZNi1O-MjG2QkfiD+gjkZ_3cBE+bRXp+JqcrsAdA@mail.gmail.com
Whole thread Raw
Responses Re: [pgAdmin4] To make session cookie more secure (Server mode)  (Dave Page <dpage@pgadmin.org>)
List pgadmin-hackers
Hi,

PFA minor patch to make to make session cookie more secure in Server mode.
We will set SESSION_COOKIE_SAMESITE='Lax' in the config file. 
'Lax' option prevents sending cookies with CSRF-prone requests from external sites, such as submitting a form.
RM#3342

P
​lease review.

--
Regards,
Murtuza Zabuawala
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company

Attachment

pgadmin-hackers by date:

Previous
From: Akshay Joshi
Date:
Subject: Re: [pgAdmin4][Patch] Feature #3270 Add support for runningregression tests against Firefox
Next
From: Akshay Joshi
Date:
Subject: pgAdmin 4 commit: Fixed query tool keyboard issue where arrow keyswere