Improved cookie security
-
The cookie
swpm_session
is currently not using thehttpOnly
andsecure
cookie flag. I cannot see that the cookie is used by any JavaScript, therefore theHttpOnly
flag should be okay. If HTTPS is available, thesecure
flag would also be a good idea.I could not find an issue tracker or development repo where I could raise a ticket or contribute a PR. If there is one, please let me know.
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
- The topic ‘Improved cookie security’ is closed to new replies.