According to the stackoverflow answer below, it is recommended to not include a trailing / in cookies' path. By removing the trailing / for our cookies path value, people's browsers visiting grafana will pass the cookie not only to /grafana/ sub paths but also to /grafana sub paths. This commit avoids the situation where a user would visit http://localhost/grafana, get redirected to http://localhost/grafana/login, and following login get redirected back to http://localhost/grafana, but since the grafana_session cookie isn't passed along get redirected back once more to http://localhost/grafana/login. ref: https://stackoverflow.com/questions/36131023/setting-a-slash-on-cookie-path/53784228#53784228 ref: https://tools.ietf.org/html/rfc6265#section-5.1.4
This commit is contained in:
@@ -14,8 +14,12 @@ type CookieOptions struct {
|
||||
}
|
||||
|
||||
func newCookieOptions() CookieOptions {
|
||||
path := "/"
|
||||
if len(setting.AppSubUrl) > 0 {
|
||||
path = setting.AppSubUrl
|
||||
}
|
||||
return CookieOptions{
|
||||
Path: setting.AppSubUrl + "/",
|
||||
Path: path,
|
||||
Secure: setting.CookieSecure,
|
||||
SameSiteDisabled: setting.CookieSameSiteDisabled,
|
||||
SameSiteMode: setting.CookieSameSiteMode,
|
||||
|
||||
Reference in New Issue
Block a user