secure session cookie in servicestack -



secure session cookie in servicestack -

can tell me how servicestack utilize secure attribute on session cookies cookie sent on https based requests. of import helping prevent session hijacking. tests far show if servicestack authentication in done on https website still sets cookies no secure meaning if there http requests in site cookies captured.

is there setting or config alter this?

you can utilize config.onlysendsessioncookiessecurely alternative tell servicestack add together secure cookie sessionids in https requests:

setconfig(new hostconfig { onlysendsessioncookiessecurely = true });

servicestack session-cookies

Comments

Popular posts from this blog

php - Android app custom user registration and login with cookie using facebook sdk -

c# - Create a Notification Object (Email or Page) At Run Time -- Dependency Injection or Factory -

Set Up Of Common Name Of SSL Certificate To Protect Plesk Panel -