diff --git a/config/initializers/secure_headers.rb b/config/initializers/secure_headers.rb index 0c50fa271b0..3b7b755c7f5 100644 --- a/config/initializers/secure_headers.rb +++ b/config/initializers/secure_headers.rb @@ -45,7 +45,7 @@ secure: true, # mark all cookies as "Secure" httponly: true, # mark all cookies as "HttpOnly" samesite: { - strict: true # mark all cookies as SameSite=Strict. + lax: true # mark all cookies as SameSite=Strict. }, }