Backport SameSite=None cookie from upstream to support latest browsers
Issue
- We need a version (fix) of mod_auth_mellon.so for (RHEL 7) that supports
MellonCookieSameSite None
. - With Chrome 80, Chrome will treat cookies that have no declared SameSite value as
SameSite=Lax
cookies. Only cookies with theSameSite=None;
Secure setting will be available for external access, provided they are being accessed from secure connections.
In mellon, this could prevent 3rd party IDPs from being accessed, see the upstream commit
Environment
- Red Hat Enterprise Linux (RHEL)
- 8
- 7
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.