diff --git a/config/initializers/devise.rb b/config/initializers/devise.rb index fe6d675af..d5791ce6a 100644 --- a/config/initializers/devise.rb +++ b/config/initializers/devise.rb @@ -175,7 +175,7 @@ # Options to be passed to the created cookie. For instance, you can set # secure: true in order to force SSL only cookies. config.rememberable_options = { - same_site: :strict, + same_site: :lax, secure: Rails.application.config.force_ssl } diff --git a/config/initializers/session_storage.rb b/config/initializers/session_storage.rb index ebe03b1d8..ab06b8bf8 100644 --- a/config/initializers/session_storage.rb +++ b/config/initializers/session_storage.rb @@ -1,5 +1,5 @@ Rails.application.config.session_store :cookie_store, expire_after: 14.days, key: "_manyfold_session", - same_site: :strict, + same_site: :lax, secure: Rails.application.config.force_ssl