Project

General

Profile

Actions

Feature #20935

closed

Set autologin cookie as secure by default when using https

Added by Jean-Philippe Lang over 10 years ago. Updated over 10 years ago.

Status:
Closed
Priority:
Normal
Category:
Security
Target version:
Resolution:
Fixed

Description

The secure flag for the autologin cookie can be configured in configuration.yml. Instead of setting it to false by default, it should be set to true when using SSL.


Related issues

Related to Redmine - Feature #21697: Set secure flag of the session cookie depending on original requestReopenedActions
Actions

Also available in: Atom PDF