Set HttpOnly attribute to SID cookie

This commit is contained in:
Chocobo1 2017-03-21 15:24:41 +08:00 committed by sledgehammer999
commit bf8a438a6f
No known key found for this signature in database
GPG key ID: 6E4A2D025B7CC9A2

View file

@ -362,6 +362,7 @@ bool AbstractWebApplication::sessionStart()
sessions_[session_->id] = session_; sessions_[session_->id] = session_;
QNetworkCookie cookie(C_SID, session_->id.toUtf8()); QNetworkCookie cookie(C_SID, session_->id.toUtf8());
cookie.setHttpOnly(true);
cookie.setPath(QLatin1String("/")); cookie.setPath(QLatin1String("/"));
header(Http::HEADER_SET_COOKIE, cookie.toRawForm()); header(Http::HEADER_SET_COOKIE, cookie.toRawForm());