Merge pull request #3547 from sbwalker/dev
set authentication cookie to HttpOnly
This commit is contained in:
commit
c832d61409
|
@ -124,7 +124,7 @@ namespace Microsoft.Extensions.DependencyInjection
|
|||
// note that ConfigureApplicationCookie internally uses an ApplicationScheme of "Identity.Application"
|
||||
services.ConfigureApplicationCookie(options =>
|
||||
{
|
||||
options.Cookie.HttpOnly = false;
|
||||
options.Cookie.HttpOnly = true;
|
||||
options.Cookie.SameSite = SameSiteMode.Strict;
|
||||
options.Cookie.SecurePolicy = CookieSecurePolicy.SameAsRequest;
|
||||
options.Events.OnRedirectToLogin = context =>
|
||||
|
|
Loading…
Reference in New Issue
Block a user