Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WebStyle: HttpOnly cookie attribute #3065

Merged

Conversation

tiborsimko
Copy link
Member

Signed-off-by: Tibor Simko [email protected]

@kaplun
Copy link
Member

kaplun commented Apr 28, 2015

@tiborsimko have you checked if BibEdit (ajax-based) still works?

@tiborsimko
Copy link
Member Author

@kaplun Yes, I did. (Just one field value change, no auto-completion etc.)

@kaplun
Copy link
Member

kaplun commented Apr 28, 2015

👍 good for me

* SECURITY Adds back the `HttpOnly` cookie attribute in order to better
  protect against potential XSS vulnerabilities.  (closes inveniosoftware#3064)

Signed-off-by: Tibor Simko <[email protected]>
Reviewed-by: Samuele Kaplun <[email protected]>
@tiborsimko tiborsimko merged commit e83f600 into inveniosoftware:maint-1.0 Apr 28, 2015
@tiborsimko
Copy link
Member Author

Reviewed-by: Samuele Kaplun <[email protected]>

Thanks, amended commit log message, and merged as e83f600.

@tiborsimko tiborsimko deleted the set-cookie-http-only branch April 28, 2015 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants