MDL-80835 enrol_lti: add partitioning support for OIDC state cookie

Adds the property that is required by Chrome to opt-in to its 3rd party
cookie partitioning solution, CHIPS. This specific change ensures the
'state' cookie, used in the OIDC handshake, has partitioning support.
This cookie can be partitioned unconditionally, since it's a cookie
controlled by the library and one we don't expect to be set without
partitioning elsewhere.
This commit is contained in:
Jake Dallimore
2024-03-21 15:39:06 +08:00
parent d225ecddbf
commit 2dc10f656b
2 changed files with 5 additions and 0 deletions
+1
View File
@@ -4,6 +4,7 @@ This library is a patched for use in Moodle - it requires the following changes
1. Removal of phpseclib dependency (replaces a single call with openssl equivalent)
2. Apply the fix from https://github.com/packbackbooks/lti-1-3-php-library/pull/107. If this is already merged upstream, please
remove this line.
3. The Packback\Lti1p3\ImsStorage\ImsCookie::setCookie() method has been locally patched to opt-in to Chrome cookie partitioning.
To upgrade to a new version of this library:
1. Clone the latest version of the upstream library from github:
+4
View File
@@ -2,6 +2,7 @@
namespace Packback\Lti1p3\ImsStorage;
use auth_lti\local\ltiadvantage\utility\cookie_helper;
use Packback\Lti1p3\Interfaces\ICookie;
class ImsCookie implements ICookie
@@ -33,6 +34,9 @@ class ImsCookie implements ICookie
setcookie($name, $value, array_merge($cookie_options, $same_site_options, $options));
// Necessary, since partitioned can't be set via setcookie yet.
cookie_helper::add_attributes_to_cookie_response_header($name, ['Partitioned']);
// Set a second fallback cookie in the event that "SameSite" is not supported
setcookie('LEGACY_'.$name, $value, array_merge($cookie_options, $options));
}