Skip to content

Fix cookie path for non-default context path#1273

Open
zhangyoufu wants to merge 1 commit intosissbruecker:masterfrom
zhangyoufu:patch-1
Open

Fix cookie path for non-default context path#1273
zhangyoufu wants to merge 1 commit intosissbruecker:masterfrom
zhangyoufu:patch-1

Conversation

@zhangyoufu
Copy link
Copy Markdown

@zhangyoufu zhangyoufu commented Jan 8, 2026

Cookie path did not respect LD_CONTEXT_PATH.
Sensitive cookies like csrftoken and sessionid may be leaked to other applications hosted on the same origin.

@zhangyoufu
Copy link
Copy Markdown
Author

Hi @sissbruecker, when you have a moment, could you please take a look at this PR? Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant