gh-136992: Add "None" as valid `SameSite` value as per RFC 6265bis (#137040)
The "SameSite" attribute defined in RFC 6265bis [1] allows the "Strict", "Lax" and "None" enforcement modes. We already documented "Strict" and "Lax" as being valid values but "None" was missing from the list. While the RFC has not been formally approved, modern browsers support the "None" value [2, 3] thereby making sense to document it. [1]: https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-rfc6265bis [2]: https://developers.google.com/search/blog/2020/01/get-ready-for-new-samesitenone-secure [3]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#none --------- Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com>
I
Iqra Khan committed
ae8b7d710020dfd336edd399fa35525dfe8fc049
Parent: cfd6da8
Committed by GitHub <noreply@github.com>
on 7/27/2025, 8:27:08 AM