FIX: After SessionRegenerateID, beegosessionID cookie's secure flag is missing (#5007)
- Add cookie.Secure, cookie.Domain, cookie.SameSite
This commit is contained in:
parent
7d8a2592db
commit
a451f398a3
@ -328,6 +328,9 @@ func (manager *Manager) SessionRegenerateID(w http.ResponseWriter, r *http.Reque
|
||||
cookie.Value = url.QueryEscape(sid)
|
||||
cookie.HttpOnly = true
|
||||
cookie.Path = "/"
|
||||
cookie.Secure = manager.isSecure(r)
|
||||
cookie.Domain = manager.config.Domain
|
||||
cookie.SameSite = manager.config.CookieSameSite
|
||||
}
|
||||
if manager.config.CookieLifeTime > 0 {
|
||||
cookie.MaxAge = manager.config.CookieLifeTime
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user