Page MenuHomePhabricator

[keyserver] Stop sending http cookies
ClosedPublic

Authored by michal on Sep 25 2023, 7:33 AM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Nov 7, 11:46 PM
Unknown Object (File)
Thu, Nov 7, 11:46 PM
Unknown Object (File)
Thu, Nov 7, 11:36 PM
Unknown Object (File)
Thu, Nov 7, 7:32 PM
Unknown Object (File)
Wed, Oct 23, 2:44 AM
Unknown Object (File)
Wed, Oct 23, 2:41 AM
Unknown Object (File)
Sat, Oct 19, 7:42 AM
Unknown Object (File)
Sat, Oct 19, 7:10 AM
Subscribers

Details

Summary

ENG-4747
Depends on D9288

We want to stop sending browser cookies on requests from the keyserver. The only exception is for website-responders where we send back any cookies we get. This is done so that they are updated to httpOnly: false and so older clients that will update to redux cookies can migrate.

Test Plan
  • Check that the migration still works
  • Check that the web app still works
  • Check that the cookie lifespan is still updated

Diff Detail

Repository
rCOMM Comm
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

This revision is now accepted and ready to land.Sep 26 2023, 2:59 AM