Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The token cookie should be Secure #16

Open
mattiasgrenfeldt opened this issue Feb 27, 2021 · 0 comments
Open

The token cookie should be Secure #16

mattiasgrenfeldt opened this issue Feb 27, 2021 · 0 comments

Comments

@mattiasgrenfeldt
Copy link
Contributor

#13 added so that the login token is stored in a cookie instead of a GET-parameter. The cookie should also have the secure attribute so that it is only sent over HTTPS. But for local development this should be disabled. So this should be controlled by a DEV or DEBUG environment variable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant