From 8a577f8037e9615fd20e73838a50a28696b1f7fb Mon Sep 17 00:00:00 2001 From: Peter Ivanov Date: Tue, 10 Aug 2021 15:49:16 +0300 Subject: [PATCH] update --- config/session.php | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/config/session.php b/config/session.php index 38e01099230..faddaf11e04 100644 --- a/config/session.php +++ b/config/session.php @@ -150,4 +150,20 @@ 'secure' => false, + /* + |-------------------------------------------------------------------------- + | Same-Site Cookies + |-------------------------------------------------------------------------- + | + | This option determines how your cookies behave when cross-site requests + | take place, and can be used to mitigate CSRF attacks. By default, we + | do not enable this as other CSRF protection services are in place. + | + | Supported: "lax", "strict" + | + */ + + 'same_site' => "lax", + + ];