Skip to content

Commit fada626

Browse files
authored
Fix NonceCookie/CorrelationCookie dotnet#44853 (dotnet#45247)
1 parent ce98f65 commit fada626

File tree

3 files changed

+3
-3
lines changed

3 files changed

+3
-3
lines changed

Diff for: src/Security/Authentication/Core/src/RemoteAuthenticationOptions.cs

+1-1
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ public RemoteAuthenticationOptions()
2626
Name = CorrelationPrefix,
2727
HttpOnly = true,
2828
SameSite = SameSiteMode.None,
29-
SecurePolicy = CookieSecurePolicy.SameAsRequest,
29+
SecurePolicy = CookieSecurePolicy.Always,
3030
IsEssential = true,
3131
};
3232
}

Diff for: src/Security/Authentication/OpenIdConnect/src/OpenIdConnectOptions.cs

+1-1
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ public OpenIdConnectOptions()
7070
Name = OpenIdConnectDefaults.CookieNoncePrefix,
7171
HttpOnly = true,
7272
SameSite = SameSiteMode.None,
73-
SecurePolicy = CookieSecurePolicy.SameAsRequest,
73+
SecurePolicy = CookieSecurePolicy.Always,
7474
IsEssential = true,
7575
};
7676
}

Diff for: src/Security/Authentication/test/OpenIdConnect/OpenIdConnectTests.cs

+1-1
Original file line numberDiff line numberDiff line change
@@ -480,7 +480,7 @@ public void CanCreateOpenIdConnectCookiesFromConfig()
480480
Assert.Equal(OpenIdConnectDefaults.CookieNoncePrefix, options.NonceCookie.Name);
481481
Assert.True(options.NonceCookie.IsEssential);
482482
Assert.True(options.NonceCookie.HttpOnly);
483-
Assert.Equal(CookieSecurePolicy.SameAsRequest, options.NonceCookie.SecurePolicy);
483+
Assert.Equal(CookieSecurePolicy.Always, options.NonceCookie.SecurePolicy);
484484
Assert.Equal(TimeSpan.FromMinutes(1), options.BackchannelTimeout);
485485
}
486486

0 commit comments

Comments
 (0)