No child items are currently assigned. Use child items to break down this issue into smaller parts.
Link issues together to show that they're related. Learn more.
changed the description
Implementing CSRF token may not feasible for now, so i just use same site flag on session cookie to reduce the threat. #ff964085