summaryrefslogtreecommitdiff
path: root/django/http
diff options
context:
space:
mode:
authorMariusz Felisiak <felisiak.mariusz@gmail.com>2020-07-16 08:16:58 +0200
committerGitHub <noreply@github.com>2020-07-16 08:16:58 +0200
commit240cbb63bf9965c63d7a3cc9032f91410f414d46 (patch)
tree14d5fcd1e195f9ceae2c04082a56dfc978f291cb /django/http
parent156a2138db20abc89933121e4ff2ee2ce56a173a (diff)
Fixed #31790 -- Fixed setting SameSite and Secure cookies flags in HttpResponse.delete_cookie().
Cookies with the "SameSite" flag set to None and without the "secure" flag will be soon rejected by latest browser versions. This affects sessions and messages cookies.
Diffstat (limited to 'django/http')
-rw-r--r--django/http/response.py15
1 files changed, 10 insertions, 5 deletions
diff --git a/django/http/response.py b/django/http/response.py
index e00bcacefb..c0ed93c44e 100644
--- a/django/http/response.py
+++ b/django/http/response.py
@@ -210,13 +210,18 @@ class HttpResponseBase:
value = signing.get_cookie_signer(salt=key + salt).sign(value)
return self.set_cookie(key, value, **kwargs)
- def delete_cookie(self, key, path='/', domain=None):
- # Most browsers ignore the Set-Cookie header if the cookie name starts
- # with __Host- or __Secure- and the cookie doesn't use the secure flag.
- secure = key.startswith(('__Secure-', '__Host-'))
+ def delete_cookie(self, key, path='/', domain=None, samesite=None):
+ # Browsers can ignore the Set-Cookie header if the cookie doesn't use
+ # the secure flag and:
+ # - the cookie name starts with "__Host-" or "__Secure-", or
+ # - the samesite is "none".
+ secure = (
+ key.startswith(('__Secure-', '__Host-')) or
+ (samesite and samesite.lower() == 'none')
+ )
self.set_cookie(
key, max_age=0, path=path, domain=domain, secure=secure,
- expires='Thu, 01 Jan 1970 00:00:00 GMT',
+ expires='Thu, 01 Jan 1970 00:00:00 GMT', samesite=samesite,
)
# Common methods used by subclasses