GFlisch / Arc4u

Apache License 2.0
22 stars 17 forks source link

Cookie policies #110

Open vvdb-architecture opened 5 months ago

vvdb-architecture commented 5 months ago

Recent PEN test reports noticed that cookies issued by Arc4 (via AddCookie) are not having SameSite (or HttpsOnly, which is called Secure in .NET) enabled.

We should consider: