koajs / generic-session

koa session store with memory, redis or others.
MIT License
414 stars 65 forks source link

sameSite: true by default? #128

Closed niftylettuce closed 4 years ago

niftylettuce commented 6 years ago

per https://scotthelme.co.uk/csrf-is-dead/ and since expressjs/cookies supports same site, we should probably set sameSite: true by default?