Skip to content

Fix #3622: Ensure SameSite is Lax when null is provided to DefaultCookieSerializer#3629

Open
Khyojae wants to merge 1 commit intospring-projects:3.3.xfrom
Khyojae:fix/issue-3622-samesite-fix
Open

Fix #3622: Ensure SameSite is Lax when null is provided to DefaultCookieSerializer#3629
Khyojae wants to merge 1 commit intospring-projects:3.3.xfrom
Khyojae:fix/issue-3622-samesite-fix

Conversation

@Khyojae
Copy link

@Khyojae Khyojae commented Jan 23, 2026

Resolves #3622

This PR ensures that DefaultCookieSerializer falls back to the default "Lax" SameSite attribute when null is explicitly provided. This prevents the SameSite attribute from being omitted in certain auto-configuration scenarios in Spring Boot 3.3+.

I've also added a regression test to verify this behavior.

…d to DefaultCookieSerializer

Signed-off-by: Khyojae <khjae201@gmail.com>
@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Jan 23, 2026
@DamianFekete
Copy link

This is a bad PR, should be closed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: waiting-for-triage An issue we've not yet triaged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants