misc: set secure and http-only for cookie 'cookie-test' (#76809) #43

Merged
bdauvergne merged 1 commits from wip/76810-poser-secure-et-HttpOnly-sur-le into main 2023-04-20 19:20:48 +02:00
1 changed files with 8 additions and 1 deletions

View File

@ -264,7 +264,14 @@ class CookieTestMiddleware(MiddlewareMixin):
def process_response(self, request, response):
if not self.check(request):
# set test cookie for 1 year
response.set_cookie(self.COOKIE_NAME, '1', max_age=365 * 24 * 3600, samesite='Lax')
response.set_cookie(
self.COOKIE_NAME,
'1',
max_age=365 * 24 * 3600,
secure=settings.SESSION_COOKIE_SECURE,
httponly=True,
samesite='Lax',
)
return response