mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #06795
[Bug 843573] Re: Enable secure cookies is wwwroot is set to HTTPS
https://reviews.mahara.org/844
** Changed in: mahara
Status: Triaged => In Progress
** Changed in: mahara
Status: In Progress => Fix Committed
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
https://bugs.launchpad.net/bugs/843573
Title:
Enable secure cookies is wwwroot is set to HTTPS
Status in Mahara ePortfolio:
Fix Committed
Bug description:
To further increase our protection against https-to-http downgrades,
we should only set Secure Cookies (the ones that browsers will only
send over HTTPS) when the wwwroot points to https or when a ssl proxy
is enabled.
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/843573/+subscriptions
References