diff --git a/server/middlewares.go b/server/middlewares.go index 9f291e26a..52399da34 100644 --- a/server/middlewares.go +++ b/server/middlewares.go @@ -112,7 +112,7 @@ func clientUniqueIdAdder(next http.Handler) http.Handler { MaxAge: consts.CookieExpiry, HttpOnly: true, Secure: true, - SameSite: http.SameSiteNoneMode, + SameSite: http.SameSiteStrictMode, Path: "/", } http.SetCookie(w, c) diff --git a/server/subsonic/middlewares.go b/server/subsonic/middlewares.go index b66f23eff..50345a405 100644 --- a/server/subsonic/middlewares.go +++ b/server/subsonic/middlewares.go @@ -161,6 +161,7 @@ func getPlayer(players core.Players) func(next http.Handler) http.Handler { Value: player.ID, MaxAge: consts.CookieExpiry, HttpOnly: true, + SameSite: http.SameSiteStrictMode, Path: "/", } http.SetCookie(w, cookie)