From d63de5471bf3c8a40bdc9f9e3b5332d2f0b1f2a9 Mon Sep 17 00:00:00 2001 From: Thomas Citharel Date: Wed, 17 Oct 2018 09:24:21 +0200 Subject: [PATCH] Don't require Same Site Cookies on assets Which can be used for public iframe embeeding See https://github.com/nextcloud/calendar/issues/169 Signed-off-by: Thomas Citharel --- apps/theming/lib/Controller/ThemingController.php | 2 ++ core/Controller/CssController.php | 1 + core/Controller/JsController.php | 1 + core/Controller/SvgController.php | 2 ++ 4 files changed, 6 insertions(+) diff --git a/apps/theming/lib/Controller/ThemingController.php b/apps/theming/lib/Controller/ThemingController.php index a1fa5e5783..cc8af2cae3 100644 --- a/apps/theming/lib/Controller/ThemingController.php +++ b/apps/theming/lib/Controller/ThemingController.php @@ -397,6 +397,7 @@ class ThemingController extends Controller { /** * @NoCSRFRequired * @PublicPage + * @NoSameSiteCookieRequired * * @return FileDisplayResponse|NotFoundResponse * @throws NotPermittedException @@ -428,6 +429,7 @@ class ThemingController extends Controller { /** * @NoCSRFRequired * @PublicPage + * @NoSameSiteCookieRequired * * @return DataDownloadResponse */ diff --git a/core/Controller/CssController.php b/core/Controller/CssController.php index c8458eab29..901074d028 100644 --- a/core/Controller/CssController.php +++ b/core/Controller/CssController.php @@ -62,6 +62,7 @@ class CssController extends Controller { /** * @PublicPage * @NoCSRFRequired + * @NoSameSiteCookieRequired * * @param string $fileName css filename with extension * @param string $appName css folder name diff --git a/core/Controller/JsController.php b/core/Controller/JsController.php index f91fe8f75d..cdf22eda5f 100644 --- a/core/Controller/JsController.php +++ b/core/Controller/JsController.php @@ -56,6 +56,7 @@ class JsController extends Controller { /** * @PublicPage * @NoCSRFRequired + * @NoSameSiteCookieRequired * * @param string $fileName js filename with extension * @param string $appName js folder name diff --git a/core/Controller/SvgController.php b/core/Controller/SvgController.php index c6bf7b94da..f7159dd9fe 100644 --- a/core/Controller/SvgController.php +++ b/core/Controller/SvgController.php @@ -57,6 +57,7 @@ class SvgController extends Controller { /** * @PublicPage * @NoCSRFRequired + * @NoSameSiteCookieRequired * * Generate svg from filename with the requested color * @@ -73,6 +74,7 @@ class SvgController extends Controller { /** * @PublicPage * @NoCSRFRequired + * @NoSameSiteCookieRequired * * Generate svg from filename with the requested color *