Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

Secure Cookies should only be transmitted over SSL

#5629

If a cookie is marked 'secure' it should only be sent to the browser over SSL or else it may be intercepted.

This can be confusing (especially in development mode) because it will no-op if the request is not SSL and it can be hard to track down to :secure => true in the session options.

I am setting the flag as 'secure', older versions of Rails have set it to 'Secure' but I cannot find a spec that specifies if the capitalization matters.

Reported by W. Andrew Loe III · September 13th, 2010 @ 10:34 PM

State: committed
Milestone: none
Assigned to: nobody
Importance: Low

Activity

  1. W. Andrew Loe III
    W. Andrew Loe III

    If this is accepted I will backport to 3-0-stable and 2-3-stable.

    September 13th, 2010 @ 10:34 PM

  2. Aaron Patterson
    Aaron Patterson
    • State changed from new to committed
    • Importance changed from to Low

    I've applied to master. :-)

    Send me the backports and I'll apply them as well.

    September 13th, 2010 @ 11:12 PM

  3. W. Andrew Loe III
    W. Andrew Loe III

    Turns out the patch is exactly the same for 3-0-stable.

    2-3-stable patch is attached. The tests for 2-3-stable are seemingly duplicated but I deemed it necessary since the CookieStore implements it own call() that is subtly different. The MemCacheStore tests exercise the AbstractStore implementation.

    September 14th, 2010 @ 12:28 AM

  4. W. Andrew Loe III