Skip to content

Conversation

@T-Spoon
Copy link
Contributor

@T-Spoon T-Spoon commented Mar 7, 2021

Anyone upgrading to >= v6.18.27 will have all their cookies invalidated.

This seems like an important point to highlight that I didn't see mentioned anywhere. I only found it after basically doing a binary search through upgrades to find out which version borked our cookies.

For some apps this means that all their users will be logged out at once - which could have a bunch of implications (not to mention an annoyance for the users)

I may have just completely missed the memo on this - but there was no info on the PR (#33662) and the discussion is currently locked.

Supercedes #36489 (changed to target 6.x instead of 8.x)

After this this change any existing cookies will be invalid (which may have implications for some apps)
@GrahamCampbell GrahamCampbell changed the title [8.x] Update changelog for v6.18.27 with upgrade info around cookies [6.x] Update changelog for v6.18.27 with upgrade info around cookies Mar 7, 2021
@derekmd
Copy link
Contributor

derekmd commented Mar 7, 2021

I may have just completely missed the memo on this - but there was no info on the PR (#33662) and the discussion is currently locked.

https://blog.laravel.com/laravel-cookie-security-releases covers it.

@T-Spoon
Copy link
Contributor Author

T-Spoon commented Mar 7, 2021

I may have just completely missed the memo on this - but there was no info on the PR (#33662) and the discussion is currently locked.

https://blog.laravel.com/laravel-cookie-security-releases covers it.

Awesome. I've added a link to that in the changelog.

I still think it's worth merging this PR (or similar) to mention this info in the changelog - as people may not think to look through the blog post archive to find this info (I actually did scan back through many pages of the blog but clearly missed that one!)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants