Merge pull request #4990 from dada0z/develop
bugfix: Csrf token should be Secure and httpOnly, but not now
This commit is contained in:
commit
7fa92f927a
@ -270,7 +270,7 @@ func (ctx *Context) XSRFToken(key string, expire int64) string {
|
|||||||
if !ok {
|
if !ok {
|
||||||
token = string(utils.RandomCreateBytes(32))
|
token = string(utils.RandomCreateBytes(32))
|
||||||
// TODO make it configurable
|
// TODO make it configurable
|
||||||
ctx.SetSecureCookie(key, "_xsrf", token, expire, "/", "")
|
ctx.SetSecureCookie(key, "_xsrf", token, expire, "/", "", true, true)
|
||||||
}
|
}
|
||||||
ctx._xsrfToken = token
|
ctx._xsrfToken = token
|
||||||
}
|
}
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user