瀏覽代碼

mark redirect_to cookie as http only

closes #10829
bergquist 7 年之前
父節點
當前提交
0ab0343995
共有 1 個文件被更改,包括 2 次插入1 次删除
  1. 2 1
      pkg/middleware/auth.go

+ 2 - 1
pkg/middleware/auth.go

@@ -51,7 +51,8 @@ func notAuthorized(c *Context) {
 		return
 	}
 
-	c.SetCookie("redirect_to", url.QueryEscape(setting.AppSubUrl+c.Req.RequestURI), 0, setting.AppSubUrl+"/")
+	c.SetCookie("redirect_to", url.QueryEscape(setting.AppSubUrl+c.Req.RequestURI), 0, setting.AppSubUrl+"/", nil, false, true)
+
 	c.Redirect(setting.AppSubUrl + "/login")
 }