diff --git a/src/backend/InvenTree/InvenTree/settings.py b/src/backend/InvenTree/InvenTree/settings.py index 29d8211f90a4..cb4edc3a0e79 100644 --- a/src/backend/InvenTree/InvenTree/settings.py +++ b/src/backend/InvenTree/InvenTree/settings.py @@ -1218,7 +1218,9 @@ if DEBUG else ( SESSION_COOKIE_SAMESITE == 'None' - or get_boolean_setting('INVENTREE_SESSION_COOKIE_SECURE', 'cookie.secure', True) + or get_boolean_setting( + 'INVENTREE_SESSION_COOKIE_SECURE', 'cookie.secure', False + ) ) ) diff --git a/src/backend/InvenTree/config_template.yaml b/src/backend/InvenTree/config_template.yaml index 7dcdde460da5..99213ce9c3c7 100644 --- a/src/backend/InvenTree/config_template.yaml +++ b/src/backend/InvenTree/config_template.yaml @@ -124,9 +124,9 @@ use_x_forwarded_host: false use_x_forwarded_port: false # Cookie settings (nominally the default settings should be fine) -#cookie: -# secure: false -# samesite: false +cookie: + secure: false + samesite: false # Cross Origin Resource Sharing (CORS) settings (see https://github.com/adamchainz/django-cors-headers) cors: