Merge pull request #4990 from dada0z/develop
bugfix: Csrf token should be Secure and httpOnly, but not now
This commit is contained in:
commit
7fa92f927a
@ -270,7 +270,7 @@ func (ctx *Context) XSRFToken(key string, expire int64) string {
|
||||
if !ok {
|
||||
token = string(utils.RandomCreateBytes(32))
|
||||
// TODO make it configurable
|
||||
ctx.SetSecureCookie(key, "_xsrf", token, expire, "/", "")
|
||||
ctx.SetSecureCookie(key, "_xsrf", token, expire, "/", "", true, true)
|
||||
}
|
||||
ctx._xsrfToken = token
|
||||
}
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user