Adds AntiForgery Cookie setting options.Cookie.HttpOnly = true;
This commit is contained in:
parent
a5f8651941
commit
dcf919fb36
|
@ -100,6 +100,7 @@ namespace Oqtane
|
|||
options.Cookie.Name = Constants.AntiForgeryTokenCookieName;
|
||||
options.Cookie.SameSite = SameSiteMode.Strict;
|
||||
options.Cookie.SecurePolicy = CookieSecurePolicy.SameAsRequest;
|
||||
options.Cookie.HttpOnly = true;
|
||||
});
|
||||
|
||||
services.AddIdentityCore<IdentityUser>(options => { })
|
||||
|
|
Loading…
Reference in New Issue
Block a user