Skip to content

Session cookie's SameSite configuration is ignored when enabling spring session #3622

@gbaso

Description

@gbaso

Describe the bug
When enabling Spring Session via @EnableSpringHttpSession, configuration property server.servlet.session.cookie.same-site is ignored. This is a regression from Spring 6.

To Reproduce
Include org.springframework.session:spring-session-core in your dependencies and create a configuration class with @EnableSpringHttpSession.

Expected behavior
Session cookie created by SessionRepositoryFilter, via CookieHttpSessionIdResolver#cookieSerializer, should respect server.servlet.session.cookie.same-site.

Sample

https://github.com/gbaso/spring-session-cookie

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions