Skip to content

Comments

fix(security): migrate cookie serializer from :hybrid to :json#2487

Merged
olleolleolle merged 2 commits intocodebar:masterfrom
mroderick:fix/cookie-serializer-json
Feb 18, 2026
Merged

fix(security): migrate cookie serializer from :hybrid to :json#2487
olleolleolle merged 2 commits intocodebar:masterfrom
mroderick:fix/cookie-serializer-json

Conversation

@mroderick
Copy link
Collaborator

@mroderick mroderick commented Feb 15, 2026

⚠️ This PR should be deployed at least 24h after #2486

Part 2 of 2-step migration:

  • :hybrid allowed reading existing :marshal cookies
  • New cookies are written as :json
  • After sessions expire, will switch to :json

See https://nts.strzibny.name/migrating-rails-cookies-to-json/

Part 1 of 2-step migration:
- :hybrid allows reading existing :marshal cookies
- New cookies are written as :json
- After sessions expire, will switch to :json
Final step - now using :json for all cookies (read and write)
@mroderick mroderick changed the title Fix/cookie serializer json fix(security): migrate cookie serializer from :hybrid to :json Feb 15, 2026
@olleolleolle
Copy link
Collaborator

Nice, the previous compatibility PR is merged.

@jonodrew jonodrew self-requested a review February 17, 2026 16:31
@olleolleolle olleolleolle merged commit bc1812e into codebar:master Feb 18, 2026
8 checks passed
@mroderick
Copy link
Collaborator Author

This has been merged, deployed and verified in production

@mroderick mroderick deleted the fix/cookie-serializer-json branch February 18, 2026 18:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants