Skip to content

Resolve "HackerOne reported issue: Cookie bomb vulnerability in Pages"

What does this MR do?

Documents a recommended security practice applicable to GitLab Pages domains

Are there points in the code the reviewer needs to double check?

Why was this MR needed?

We made this change for GitLab.io some time ago (see https://gitlab.com/gitlab-com/infrastructure/issues/230), but have never communicated its desirability to our users.

Screenshots (if relevant)

Does this MR meet the acceptance criteria?

What are the relevant issue numbers?

Closes #31049 (closed)

Merge request reports