Make session cookie HttpOnly and Secure
This commit is contained in:
		@@ -126,6 +126,8 @@ func createSessionCookie(app *app.App, w http.ResponseWriter, username string) (
 | 
			
		||||
		Value:    token,
 | 
			
		||||
		Path:     "/",
 | 
			
		||||
		MaxAge:   86400,
 | 
			
		||||
		HttpOnly: true,
 | 
			
		||||
		Secure:   true,
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
	http.SetCookie(w, cookie)
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user