Onion service related changes to HTTPS handling (#15560)

* Enable secure cookie flag for https only

* Disable force_ssl for .onion hosts only

Co-authored-by: Aiden McClelland <me@drbonez.dev>
This commit is contained in:
Cecylia Bocovich
2021-02-10 22:40:13 -05:00
committed by GitHub
parent d499bb031f
commit e79f8dd85c
8 changed files with 27 additions and 11 deletions

View File

@@ -0,0 +1,10 @@
SecureHeaders::Configuration.default do |config|
config.cookies = {
secure: true,
httponly: true,
samesite: {
lax: true
}
}
config.csp = SecureHeaders::OPT_OUT
end