Skip to content

Latest commit

 

History

History
12 lines (10 loc) · 473 Bytes

2021-07-21-improve-storefront-security-defaults.md

File metadata and controls

12 lines (10 loc) · 473 Bytes
title issue
Improve storefront security defaults
NEXT-13300

Core

  • Added session config cookie_samesite to lax in Core/Framework/Resources/config/packages/framework.yaml
  • Added header Referrer-Policy with value strict-origin-when-cross-origin in Core/Framework/Routing/CoreSubscriber.php

Storefront

  • Added secure and sameSite properties to cookies in Storefront/Resources/app/storefront/src/helper/storage/cookie-storage.helper.js