Blame SOURCES/0018-add-note-on-usage-of-OIDC_SET_COOKIE_APPEND-in-the-s.patch

50cc55
From d2f6572e93446d611fc66cf68d0b71cd13366d55 Mon Sep 17 00:00:00 2001
50cc55
From: Hans Zandbelt <hans.zandbelt@zmartzone.eu>
50cc55
Date: Thu, 30 Jul 2020 10:10:04 +0200
50cc55
Subject: [PATCH 18/19] add note on usage of OIDC_SET_COOKIE_APPEND in the
50cc55
 sample config/doc
50cc55
50cc55
Signed-off-by: Hans Zandbelt <hans.zandbelt@zmartzone.eu>
50cc55
(cherry picked from commit bcbdd1993e7449446cb34df696826bd8bc9d2977)
50cc55
---
50cc55
 auth_openidc.conf | 6 ++++++
50cc55
 1 file changed, 6 insertions(+)
50cc55
50cc55
diff --git a/auth_openidc.conf b/auth_openidc.conf
50cc55
index 4012df3..ce2fba7 100644
50cc55
--- a/auth_openidc.conf
50cc55
+++ b/auth_openidc.conf
50cc55
@@ -431,6 +431,12 @@
50cc55
 #   state cookie: Lax
50cc55
 #   session cookie: first time set Lax, updates (e.g. after inactivity timeout) Strict
50cc55
 #   x_csrf discovery: Strict:
50cc55
+#
50cc55
+# The default `SameSite=None` cookie appendix on `Set-Cookie` response headers can be 
50cc55
+# conditionally overridden using an environment variable in the Apache config as in:
50cc55
+#   SetEnvIf User-Agent ".*IOS.*" OIDC_SET_COOKIE_APPEND=;
50cc55
+# (since version 2.4.1)
50cc55
+#
50cc55
 # When not defined the default is Off.
50cc55
 #OIDCCookieSameSite [On|Off]
50cc55
 
50cc55
-- 
50cc55
2.26.2
50cc55