From 18ad8aaecfae154deabab6f82da0c06dcf91d4c1 Mon Sep 17 00:00:00 2001 From: shibayashi Date: Tue, 28 Aug 2018 22:34:31 +0200 Subject: [PATCH] Explicitly set 'http_only' to true --- lib/pleroma/web/endpoint.ex | 1 + 1 file changed, 1 insertion(+) diff --git a/lib/pleroma/web/endpoint.ex b/lib/pleroma/web/endpoint.ex index 17f6b9bb6..6e60c9017 100644 --- a/lib/pleroma/web/endpoint.ex +++ b/lib/pleroma/web/endpoint.ex @@ -50,6 +50,7 @@ defmodule Pleroma.Web.Endpoint do store: :cookie, key: "_pleroma_key", signing_salt: "CqaoopA2", + http_only: true, secure: Application.get_env(:pleroma, Pleroma.Web.Endpoint) |> Keyword.get(:secure_cookie_flag), extra: "SameSite=Strict"