Adds AntiForgery Cookie setting options.Cookie.HttpOnly = true;
This commit is contained in:
parent
a5f8651941
commit
dcf919fb36
@ -100,6 +100,7 @@ namespace Oqtane
|
||||
options.Cookie.Name = Constants.AntiForgeryTokenCookieName;
|
||||
options.Cookie.SameSite = SameSiteMode.Strict;
|
||||
options.Cookie.SecurePolicy = CookieSecurePolicy.SameAsRequest;
|
||||
options.Cookie.HttpOnly = true;
|
||||
});
|
||||
|
||||
services.AddIdentityCore<IdentityUser>(options => { })
|
||||
|
Reference in New Issue
Block a user