Hi,
I've created an issue and submitted a PR to make a Set-Cookie with
unspecified SameSite value Lax-by-default optional.
Since the next version of rfc6265(ter) is already doing this it might be
good to have rfc6265bis reflect the same sentiment since Firefox and
apparently Safari as well currently default to SameSite=None.
https://github.com/httpwg/http-extensions/issues/2983
https://github.com/httpwg/http-extensions/pull/2984/commits/84d43898addc96bfdd8e240a7f23729a6868a5fc
Thank you and I hope I am not too late,
Ed Guloien
Mozilla, Networking
--
last-call mailing list -- last-call@xxxxxxxx
To unsubscribe send an email to last-call-leave@xxxxxxxx