Add httponly to session cookie.

This commit is contained in:
voussoir 2020-09-09 19:19:35 -07:00
parent 2ba4a3bb91
commit cb881ed640

View file

@ -93,6 +93,7 @@ class SessionManager:
'etiquette_session',
value=session.token,
max_age=SESSION_MAX_AGE,
httponly=True,
)
return response