Skip to content

Commit c1e30c9

Browse files
authored
Add secure/httpOnly attributes to the lang cookie (#9690) (#14279)
1 parent 3c96a37 commit c1e30c9

File tree

1 file changed

+9
-7
lines changed

1 file changed

+9
-7
lines changed

routers/routes/macaron.go

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -83,13 +83,15 @@ func NewMacaron() *macaron.Macaron {
8383
}
8484

8585
m.Use(i18n.I18n(i18n.Options{
86-
SubURL: setting.AppSubURL,
87-
Files: localFiles,
88-
Langs: setting.Langs,
89-
Names: setting.Names,
90-
DefaultLang: "en-US",
91-
Redirect: false,
92-
CookieDomain: setting.SessionConfig.Domain,
86+
SubURL: setting.AppSubURL,
87+
Files: localFiles,
88+
Langs: setting.Langs,
89+
Names: setting.Names,
90+
DefaultLang: "en-US",
91+
Redirect: false,
92+
CookieHttpOnly: true,
93+
Secure: setting.SessionConfig.Secure,
94+
CookieDomain: setting.SessionConfig.Domain,
9395
}))
9496
m.Use(cache.Cacher(cache.Options{
9597
Adapter: setting.CacheService.Adapter,

0 commit comments

Comments
 (0)