Adds AntiForgery Cookie setting options.Cookie.HttpOnly = true;

This commit is contained in:
Cody 2024-08-08 12:24:42 -07:00 committed by GitHub
parent a5f8651941
commit dcf919fb36
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -100,6 +100,7 @@ namespace Oqtane
options.Cookie.Name = Constants.AntiForgeryTokenCookieName;
options.Cookie.SameSite = SameSiteMode.Strict;
options.Cookie.SecurePolicy = CookieSecurePolicy.SameAsRequest;
options.Cookie.HttpOnly = true;
});
services.AddIdentityCore<IdentityUser>(options => { })