Use localStorage instead of Cookies to store pause time (optional) #536
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
During our security review it turned out that the stored cookie doesn't have the
HttpOnly
attribute, this is not a surprise since this cannot be set from JS by design.We came to the same conclusion as @stebunovd in #475, that the usage of localStorage instead of document.cookies would be a solution.
The proposed changes introduce a new option
use_local_storage
(default: false). If true, localStorage will be used instead of cookies.The code will store the cookie expiry time under
browserupdateorg
key and will check the existence/expiry of the value when settingop.already_shown
.The key will also be deleted if expired, or
pauseFor()
(renamed from setCookie()) called with <=0.Also happy to open a new PR with cleaned up commit messages if that's a concern, although probably not an issue with a squash merge if otherwise looks good.