Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove cookies from Clear-Site-Data Header #11847

Merged
merged 1 commit into from
Oct 23, 2018
Merged

Remove cookies from Clear-Site-Data Header #11847

merged 1 commit into from
Oct 23, 2018

Commits on Oct 15, 2018

  1. Remove cookies from Clear-Site-Data Header

    In 2f87fb6 this header was introduced. The referenced documentation says:
    
    > When delivered with a response from https://example.com/clear, the following header will cause cookies associated with the origin https://example.com to be cleared, as well as cookies on any origin in the same registered domain (e.g. https://www.example.com/ and https://more.subdomains.example.com/).
    
    This also applies if `https://nextcloud.example.com/` sends the `Clear-Site-Data: "cookies"` header.
    This is not the behavior we want at this point!
    
    So I removed the deletion of cookies from the header. This has no effect on the logout process as this header is supported only recently and the logout works in old browsers as well.
    
    Signed-off-by: Patrick Conrad <conrad@iza.org>
    iPaat committed Oct 15, 2018
    Configuration menu
    Copy the full SHA
    1806baa View commit details
    Browse the repository at this point in the history