Onion service related changes to HTTPS handling (#15560)
* Enable secure cookie flag for https only * Disable force_ssl for .onion hosts only Co-authored-by: Aiden McClelland <me@drbonez.dev>
This commit is contained in:
parent
d499bb031f
commit
e79f8dd85c
8 changed files with 27 additions and 11 deletions
10
config/initializers/secureheaders.rb
Normal file
10
config/initializers/secureheaders.rb
Normal file
|
@ -0,0 +1,10 @@
|
|||
SecureHeaders::Configuration.default do |config|
|
||||
config.cookies = {
|
||||
secure: true,
|
||||
httponly: true,
|
||||
samesite: {
|
||||
lax: true
|
||||
}
|
||||
}
|
||||
config.csp = SecureHeaders::OPT_OUT
|
||||
end
|
Loading…
Add table
Add a link
Reference in a new issue