StartupAPI / users

:zap: User management tool to be used in on-line projects. Includes admin dashboard.
http://www.StartupAPI.com/
MIT License
60 stars 24 forks source link

Use SameSite cookies for auth #284

Open sergeychernyshev opened 6 years ago

sergeychernyshev commented 6 years ago

Use SameSite (first party) cookies for authentication unless specifically turned off for API or other types of integrations.

Support is currently around 57% so it can't be a measure to rely on, but can be an additional security measure: https://caniuse.com/#search=same-site