SameSite cookie from flask not being added since we have an old version of Flask

Viewed 939

I have a flask app running on my server, we're using uwsgi. Flask version: 0.11.1

Problem: Cookies returned from our flask app do not contain SameSite=None; , I tried editing our flask config file by adding these:

SESSION_COOKIE_SECURE=True,
SESSION_COOKIE_HTTPONLY=True,
SESSION_COOKIE_SAMESITE='None'

but that didn't work since our version of flask does not support SameSite.

In our nginx config:

server {
    ...
    uwsgi_pass <local_ip>;
    include uwsgi_params;
    proxy_cookie_path / "/; SameSite=None; Secure";
}

proxy_cookie_path didn't work since we are using uwsgi_pass instead of nginx proxy_pass.

Finally, the cookie in the response is handled by flask sessions, so I am not setting the value manually. Thus weren't able to use response.set_cookie()

I dug into the code of flask and have reached the dump_cookie() function where the Set-Cookie header is being added, but wasn't able to come up with a fix.

Is there a way to edit the uwsgi cookie from the nginx config? Or to edit the cookie of Flask's session?

0 Answers
Related