File tree 3 files changed +5
-5
lines changed
extensions/oidc/runtime/src/main/java/io/quarkus/oidc
integration-tests/oidc-code-flow/src
test/java/io/quarkus/it/keycloak
3 files changed +5
-5
lines changed Original file line number Diff line number Diff line change @@ -769,8 +769,8 @@ public enum ResponseMode {
769
769
/**
770
770
* SameSite attribute for the session cookie.
771
771
*/
772
- @ ConfigItem (defaultValue = "strict " )
773
- public CookieSameSite cookieSameSite = CookieSameSite .STRICT ;
772
+ @ ConfigItem (defaultValue = "lax " )
773
+ public CookieSameSite cookieSameSite = CookieSameSite .LAX ;
774
774
775
775
/**
776
776
* If this property is set to 'true' then an OIDC UserInfo endpoint will be called.
Original file line number Diff line number Diff line change @@ -107,7 +107,7 @@ quarkus.oidc.tenant-https.authentication.cookie-suffix=test
107
107
quarkus.oidc.tenant-https.authentication.error-path =/tenant-https/error
108
108
quarkus.oidc.tenant-https.authentication.pkce-required =true
109
109
quarkus.oidc.tenant-https.authentication.pkce-secret =eUk1p7UB3nFiXZGUXi0uph1Y9p34YhBU
110
- quarkus.oidc.tenant-https.authentication.cookie-same-site =lax
110
+ quarkus.oidc.tenant-https.authentication.cookie-same-site =strict
111
111
112
112
quarkus.oidc.tenant-javascript.auth-server-url =${quarkus.oidc.auth-server-url}
113
113
quarkus.oidc.tenant-javascript.client-id =quarkus-app
Original file line number Diff line number Diff line change @@ -95,7 +95,7 @@ public void testCodeFlowNoConsent() throws IOException {
95
95
96
96
Cookie sessionCookie = getSessionCookie (webClient , null );
97
97
assertNotNull (sessionCookie );
98
- assertEquals ("strict " , sessionCookie .getSameSite ());
98
+ assertEquals ("lax " , sessionCookie .getSameSite ());
99
99
100
100
webClient .getCookieManager ().clearCookies ();
101
101
}
@@ -220,7 +220,7 @@ public void testCodeFlowForceHttpsRedirectUriAndPkce() throws Exception {
220
220
assertEquals ("tenant-https:reauthenticated" , page .getBody ().asNormalizedText ());
221
221
Cookie sessionCookie = getSessionCookie (webClient , "tenant-https_test" );
222
222
assertNotNull (sessionCookie );
223
- assertEquals ("lax " , sessionCookie .getSameSite ());
223
+ assertEquals ("strict " , sessionCookie .getSameSite ());
224
224
webClient .getCookieManager ().clearCookies ();
225
225
}
226
226
}
You can’t perform that action at this time.
0 commit comments