Add Secure and SameSite cookie flags

This commit is contained in:
shibayashi 2018-08-28 00:40:58 +02:00
commit b9a642da1e
No known key found for this signature in database
GPG key ID: C10662A33EB28508
2 changed files with 5 additions and 2 deletions

View file

@ -49,7 +49,9 @@ defmodule Pleroma.Web.Endpoint do
Plug.Session,
store: :cookie,
key: "_pleroma_key",
signing_salt: "CqaoopA2"
signing_salt: "CqaoopA2",
secure: Application.get_env(:pleroma, Pleroma.Web.Endpoint) |> Keyword.get(:secure_cookie_flag),
extra: "SameSite=Lax"
)
plug(Pleroma.Web.Router)