Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What about setting Cookie with Path and SameSite=LAX? I would expect it to prevent sending cookies in that request, although I did not test it.


I tested with SameSite being Lax and Strict. Neither block the attack in Chrome. My reading of the SameSite spec indicates that it doesn't take cookie path into account.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: