Scott Lamb 560fe804d6 use SameSite=Lax instead of SameSite=Strict
To improve reliability of live streams (#59) on Safari.

Safari was dropping the cookie from websocket update requests.
(But it worked sometimes. I don't get why.) I saw folks on the Internet
thinking this related to HttpOnly:

*   https://developer.apple.com/forums/thread/104488
*   https://stackoverflow.com/q/47742807/23584

but I still see this behavior without HttpOnly. SameSite=Strict vs
SameSite=Lax appears to make a difference. Try that instead.
SameSite=Strict is pointless for us anyway as noted in a new comment.
Turning off HttpOnly would be more unfortunate security-wise.
2021-03-31 13:08:03 -07:00
..
2021-03-26 19:43:50 -07:00
2021-03-31 09:08:34 -07:00
2021-02-17 19:42:32 -08:00
2021-02-18 09:10:43 -08:00
2021-02-22 16:57:49 -08:00
2021-02-17 19:42:32 -08:00
2021-03-04 15:01:18 -08:00
2021-02-17 19:42:32 -08:00
2021-03-15 23:26:23 -07:00