Project

General

Profile

Actions

Feature #20935

closed

Set autologin cookie as secure by default when using https

Added by Jean-Philippe Lang over 8 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Normal
Category:
Security
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed

Description

The secure flag for the autologin cookie can be configured in configuration.yml. Instead of setting it to false by default, it should be set to true when using SSL.


Related issues

Related to Redmine - Feature #21697: Set secure flag of the session cookie depending on original requestReopened

Actions
Actions

Also available in: Atom PDF