Skip to content

Replace client-sessions to avoid nuxt-oauth breaking #55

@Venefilyn

Description

@Venefilyn

client-sessions dependency seems largely ignored and unmaintained. Is there a different dependency that can be used instead?

One of the reasons for this is that major browsers will soon ignore cookies with SameSite=None and unset Secure attribute.

Cookie “nuxtSession” will be soon rejected because it has the “sameSite” attribute set to “none” or an invalid value, without the “secure” attribute. To know more about the “sameSite“ attribute, read https://developer.mozilla.org/docs/Web/HTTP/Headers/Set-Cookie/SameSite

Luckily, it was pushed off in Chrome to a later release. But it seems to me that it will still happen in Firefox relatively soon.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions