#142 the pagure cookie should be set with the secure attribute
Closed: Fixed None Opened 10 years ago by till.

The pagure cookie should be set with the secure attribute to make sure it is not sent via unencrypted connections by browsers not supporting HSTS:
https://www.owasp.org/index.php/SecureFlag


This should be set now, the code had the logic, only the configuration change was needed.

Log in to comment on this ticket.

Metadata