SameSite + httpOnly CSRF cookie
This commit is contained in:
parent
5c3b6351d8
commit
25fbed4d44
|
@ -182,6 +182,8 @@ func userAuthHandler(repo *owl.Repository) func(http.ResponseWriter, *http.Reque
|
|||
cookie := http.Cookie{
|
||||
Name: "csrf_token",
|
||||
Value: csrfToken,
|
||||
HttpOnly: true,
|
||||
SameSite: http.SameSiteStrictMode,
|
||||
}
|
||||
http.SetCookie(w, &cookie)
|
||||
|
||||
|
|
Loading…
Reference in New Issue