<?php
-use \Illuminate\Support\Str;
+use Illuminate\Support\Str;
/**
* Session configuration options.
// to the server if the browser has a HTTPS connection. This will keep
// the cookie from being sent to you if it can not be done securely.
'secure' => env('SESSION_SECURE_COOKIE', null)
- ?? Str::startsWith(env('APP_URL'), 'https:'),
+ ?? Str::startsWith(env('APP_URL', ''), 'https:'),
// HTTP Access Only
// Setting this value to true will prevent JavaScript from accessing the
// do not enable this as other CSRF protection services are in place.
// Options: lax, strict, none
'same_site' => 'lax',
+
+
+ // Partitioned Cookies
+ // Setting this value to true will tie the cookie to the top-level site for
+ // a cross-site context. Partitioned cookies are accepted by the browser
+ // when flagged "secure" and the Same-Site attribute is set to "none".
+ 'partitioned' => false,
];