Merge pull request #1712 from coreos-inc/force-session-cookie

Add option to force session cookies to be non-secure
This commit is contained in:
josephschorr 2016-08-11 17:18:10 -04:00 committed by GitHub
commit f2994174f3

3
app.py
View file

@ -87,7 +87,8 @@ if app.config['SECRET_KEY'] is None:
# If the "preferred" scheme is https, then http is not allowed. Therefore, ensure we have a secure # If the "preferred" scheme is https, then http is not allowed. Therefore, ensure we have a secure
# session cookie. # session cookie.
if app.config['PREFERRED_URL_SCHEME'] == 'https': if (app.config['PREFERRED_URL_SCHEME'] == 'https' and
not app.config.get('FORCE_NONSECURE_SESSION_COOKIE', False)):
app.config['SESSION_COOKIE_SECURE'] = True app.config['SESSION_COOKIE_SECURE'] = True
# Load features from config. # Load features from config.