Skip to content

Commit f4aefba

Browse files
Enforce a Strict SameSite policy on SALT API
1 parent 807392b commit f4aefba

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

salt/metalk8s/addons/ui/deployed/ingress.sls

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -30,9 +30,7 @@ metadata:
3030
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
3131
# Add strict SameSite policy for Salt API
3232
nginx.ingress.kubernetes.io/configuration-snippet: |
33-
if ($proxy_host = "salt-api") {
34-
proxy_cookie_flags ~ SameSite=Strict Secure HttpOnly;
35-
}
33+
add_header Set-Cookie "session_id=$cookie_session_id; SameSite=Strict; Secure; HttpOnly; Path=/";
3634
spec:
3735
ingressClassName: "nginx-control-plane"
3836
rules:

0 commit comments

Comments
 (0)