summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDmitriy Zaporozhets <dmitriy.zaporozhets@gmail.com>2012-10-21 06:14:36 -0700
committerDmitriy Zaporozhets <dmitriy.zaporozhets@gmail.com>2012-10-21 06:14:36 -0700
commit2ff36e74eba44b7a972fdb21774f45a27492e69e (patch)
tree639dfe3c1e27e3646ca7d3ab14619685ed35db13
parentcd9f135a660d835763d63a7ffaefb325f03faaeb (diff)
parenta58d3112620a62240c5f98f1cc0111e89de6b543 (diff)
downloadgitlab-ce-2ff36e74eba44b7a972fdb21774f45a27492e69e.tar.gz
Merge pull request #1564 from dosire/cookie_secure_setting
Secure and httponly options on cookie.
-rw-r--r--config/initializers/session_store.rb4
1 files changed, 3 insertions, 1 deletions
diff --git a/config/initializers/session_store.rb b/config/initializers/session_store.rb
index 36c5f4666a7..e777ae2b78d 100644
--- a/config/initializers/session_store.rb
+++ b/config/initializers/session_store.rb
@@ -1,6 +1,8 @@
# Be sure to restart your server when you modify this file.
-Gitlab::Application.config.session_store :cookie_store, key: '_gitlab_session'
+Gitlab::Application.config.session_store :cookie_store, key: '_gitlab_session',
+ secure: Gitlab::Application.config.force_ssl,
+ httponly: true
# Use the database for sessions instead of the cookie-based default,
# which shouldn't be used to store highly confidential information