Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
vbezhenar
on April 8, 2020
|
parent
|
context
|
favorite
| on:
Userdir URLs like https://example.org/~username/ a...
What about setting Cookie with Path and SameSite=LAX? I would expect it to prevent sending cookies in that request, although I did not test it.
justinsteven
on April 8, 2020
[–]
I tested with SameSite being Lax and Strict. Neither block the attack in Chrome. My reading of the SameSite spec indicates that it doesn't take cookie path into account.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: