浏览代码

Secure remember cookie. This doesn't enable http-only

session-cookie
父节点
当前提交
1257cadf70
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. +1
    -1
      src/app/views/login.py

+ 1
- 1
src/app/views/login.py 查看文件

@@ -63,7 +63,7 @@ class Login():
session.userid = userid session.userid = userid
if remember: if remember:
rememberme = self.rememberme(remember_timeout) rememberme = self.rememberme(remember_timeout)
web.setcookie('remember', rememberme , remember_timeout)
web.setcookie('remember', rememberme , remember_timeout, secure=True, samesite='Strict')


def check_rememberme(self): def check_rememberme(self):
""" """


正在加载...
取消
保存