【发布时间】:2020-02-05 07:09:51
【问题描述】:
了解为防止跨站点伪造而强制执行的 SameSite 更改。
来源:https://blog.chromium.org/2019/10/developers-get-ready-for-new.html
我正在尝试将其值设置为“无”并使用 Secure 作为广告。
我目前的web.config设置如下:
<system.web>
<sessionState cookieless="UseCookies"
timeout="20"
cookieSameSite="None"
xdt:Transform="Replace"
xdt:Locator="Match(cookieless)"/>
</system.web>
但我仍然收到以下错误:
A cookie associated with a resource at `mywebsite.net` was set with `SameSite=None` but without `Secure`. A future release of Chrome will only deliver cookies marked `SameSite=None` if they are also marked `Secure`.
如何在上面的 web.config 文件中指定secure 属性?任何线索将不胜感激。
【问题讨论】:
标签: c# asp.net cookies web-config samesite