<?php
-use \Illuminate\Support\Str;
+use Illuminate\Support\Str;
/**
* Session configuration options.
// The session cookie path determines the path for which the cookie will
// be regarded as available. Typically, this will be the root path of
// your application but you are free to change this when necessary.
- 'path' => '/',
+ 'path' => '/' . (explode('/', env('APP_URL', ''), 4)[3] ?? ''),
// Session Cookie Domain
// Here you may change the domain of the cookie used to identify a session
// to the server if the browser has a HTTPS connection. This will keep
// the cookie from being sent to you if it can not be done securely.
'secure' => env('SESSION_SECURE_COOKIE', null)
- ?? Str::startsWith(env('APP_URL'), 'https:'),
+ ?? Str::startsWith(env('APP_URL', ''), 'https:'),
// HTTP Access Only
// Setting this value to true will prevent JavaScript from accessing the
// do not enable this as other CSRF protection services are in place.
// Options: lax, strict, none
'same_site' => 'lax',
+
+
+ // Partitioned Cookies
+ // Setting this value to true will tie the cookie to the top-level site for
+ // a cross-site context. Partitioned cookies are accepted by the browser
+ // when flagged "secure" and the Same-Site attribute is set to "none".
+ 'partitioned' => false,
];