Add secure flag to cookie
This commit is contained in:
parent
fc36a87e72
commit
4e158b2316
|
@ -1,6 +1,9 @@
|
|||
# Be sure to restart your server when you modify this file.
|
||||
|
||||
Discourse::Application.config.session_store :cookie_store, key: '_forum_session'
|
||||
Discourse::Application.config.session_store :cookie_store, {
|
||||
key: '_forum_session',
|
||||
secure: SiteSetting.use_https
|
||||
}
|
||||
|
||||
# Use the database for sessions instead of the cookie-based default,
|
||||
# which shouldn't be used to store highly confidential information
|
||||
|
|
Loading…
Reference in New Issue