title | issue |
---|---|
Improve storefront security defaults |
NEXT-13300 |
- Added session config
cookie_samesite
tolax
inCore/Framework/Resources/config/packages/framework.yaml
- Added header
Referrer-Policy
with valuestrict-origin-when-cross-origin
inCore/Framework/Routing/CoreSubscriber.php
- Added
secure
andsameSite
properties to cookies inStorefront/Resources/app/storefront/src/helper/storage/cookie-storage.helper.js