secure session cookie in servicestack -



secure session cookie in servicestack -

can tell me how servicestack utilize secure attribute on session cookies cookie sent on https based requests. of import helping prevent session hijacking. tests far show if servicestack authentication in done on https website still sets cookies no secure meaning if there http requests in site cookies captured.

is there setting or config alter this?

you can utilize config.onlysendsessioncookiessecurely alternative tell servicestack add together secure cookie sessionids in https requests:

setconfig(new hostconfig { onlysendsessioncookiessecurely = true });

servicestack session-cookies

Comments

Popular posts from this blog

php - Android app custom user registration and login with cookie using facebook sdk -

django - Access session in user model .save() -

php - .htaccess Multiple Rewrite Rules / Prioritizing -