Skip to content

Conversation

@a-musing-moose
Copy link
Contributor

Provides secure defaults for session cookie settings. e.g. HTTP Only, and Secure.

Also add security settings to trust HTTP_X_FORWARDED_PROTO and force HTTPS via HSTS.

Resolves #78

Provides secure defaults for session cookie settings. e.g. HTTP Only,
and Secure.

Also add security settings to trust `HTTP_X_FORWARDED_PROTO` and force
HTTP via HSTS.
@a-musing-moose a-musing-moose merged commit 58212fb into main Jan 27, 2026
4 checks passed
@a-musing-moose a-musing-moose deleted the 78/cookie-hardening branch January 27, 2026 02:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Harden sessions cookie config

3 participants