Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[stable14] Remove cookies from Clear-Site-Data Header #12005

Merged
merged 1 commit into from
Oct 24, 2018
Merged

[stable14] Remove cookies from Clear-Site-Data Header #12005

merged 1 commit into from
Oct 24, 2018

Commits on Oct 24, 2018

  1. Remove cookies from Clear-Site-Data Header

    In 2f87fb6 this header was introduced. The referenced documentation says:
    
    > When delivered with a response from https://example.com/clear, the following header will cause cookies associated with the origin https://example.com to be cleared, as well as cookies on any origin in the same registered domain (e.g. https://www.example.com/ and https://more.subdomains.example.com/).
    
    This also applies if `https://nextcloud.example.com/` sends the `Clear-Site-Data: "cookies"` header.
    This is not the behavior we want at this point!
    
    So I removed the deletion of cookies from the header. This has no effect on the logout process as this header is supported only recently and the logout works in old browsers as well.
    
    Signed-off-by: Patrick Conrad <conrad@iza.org>
    (cherry picked from commit 1806baa)
    iPaat committed Oct 24, 2018
    Configuration menu
    Copy the full SHA
    bae4207 View commit details
    Browse the repository at this point in the history