How to secure classic ASP ASPSESSIONID cookie?

后端 未结 4 1883
太阳男子
太阳男子 2021-01-04 22:31

Is there a way to mark classic ASP ASPSESSIONID* cookies as secure? It appears that the ASP ISAPI handler adds that session id cookie after my page is done rendering so put

4条回答
  •  太阳男子
    2021-01-04 23:28

    The answer is no there isn't There isn't on the standard UI provided by IIS manager. However, you can enable secure cookies for the SessionID via the AspKeepSessionIDSecure Metabase value

提交回复
热议问题