Adds AntiForgery Cookie setting options.Cookie.HttpOnly = true;
This commit is contained in:
parent
a5f8651941
commit
dcf919fb36
|
@ -100,6 +100,7 @@ namespace Oqtane
|
||||||
options.Cookie.Name = Constants.AntiForgeryTokenCookieName;
|
options.Cookie.Name = Constants.AntiForgeryTokenCookieName;
|
||||||
options.Cookie.SameSite = SameSiteMode.Strict;
|
options.Cookie.SameSite = SameSiteMode.Strict;
|
||||||
options.Cookie.SecurePolicy = CookieSecurePolicy.SameAsRequest;
|
options.Cookie.SecurePolicy = CookieSecurePolicy.SameAsRequest;
|
||||||
|
options.Cookie.HttpOnly = true;
|
||||||
});
|
});
|
||||||
|
|
||||||
services.AddIdentityCore<IdentityUser>(options => { })
|
services.AddIdentityCore<IdentityUser>(options => { })
|
||||||
|
|
Loading…
Reference in New Issue
Block a user