How do I set the HttpOnly flag on a cookie in Ruby on Rails

前端 未结 5 1737
小鲜肉
小鲜肉 2021-02-05 01:08

The page Protecting Your Cookies: HttpOnly explains why making HttpOnly cookies is a good idea.

How do I set this property in Ruby on Rails?

5条回答
  •  余生分开走
    2021-02-05 01:39

    Re Laurie's answer:

    Note that the option was renamed from :http_only to :httponly (no underscore) at some point.

    In actionpack 3.0.0, that is, Ruby on Rails 3, all references to :http_only are gone.

    That threw me for a while.

提交回复
热议问题