diff --git a/CHANGELOG.md b/CHANGELOG.md index d54703eb3f1..02b4d7280a7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,7 @@ ## Breaking changes * **PagerDuty**: Change `payload.custom_details` field in PagerDuty notification to be a JSON object instead of a string. +* **Security**: The `[security]` setting `cookie_samesite` configured to `none` now renders cookies with `SameSite=None` attribute compared to before where no `SameSite` attribute was added to cookies. To get the old behavior, use value `disabled` instead of `none`. Refer to [Upgrade Grafana](https://grafana.com/docs/grafana/latest/installation/upgrading/#upgrading-to-v6-6) for more information. # 6.5.2 (2019-12-11) diff --git a/conf/defaults.ini b/conf/defaults.ini index 2a7f9ab558e..07b0070b187 100644 --- a/conf/defaults.ini +++ b/conf/defaults.ini @@ -179,7 +179,7 @@ disable_brute_force_login_protection = false # set to true if you host Grafana behind HTTPS. default is false. cookie_secure = false -# set cookie SameSite attribute. defaults to `lax`. can be set to "lax", "strict" and "none" +# set cookie SameSite attribute. defaults to `lax`. can be set to "lax", "strict", "none" and "disabled" cookie_samesite = lax # set to true if you want to allow browsers to render Grafana in a ,