set httponly on session cookie
authorJulien Cristau <julien.cristau@logilab.fr>
Tue, 30 Jun 2015 11:15:03 +0200
changeset 11579 78ba3e88a549
parent 11578 fcba04437236
child 11580 e8f8a211e503
set httponly on session cookie
pyramid_cubicweb/session.py
--- a/pyramid_cubicweb/session.py	Tue Jun 30 11:15:54 2015 +0200
+++ b/pyramid_cubicweb/session.py	Tue Jun 30 11:15:03 2015 +0200
@@ -28,7 +28,7 @@
         path='/',
         domain=None,
         secure=False,
-        httponly=False,
+        httponly=True,
         set_on_exception=True,
         timeout=1200,
         reissue_time=120,