Age | Commit message (Collapse) | Author | |
---|---|---|---|
2021-02-11 | Drop dependency on secure_headers, fix response headers (#15712) | Claire | |
* Drop dependency on secure_headers, use always_write_cookie instead * Fix cookies in Tor Hidden Services by moving configuration to application.rb * Instead of setting always_write_cookie at boot, monkey-patch ActionDispatch | |||
2021-02-11 | Onion service related changes to HTTPS handling (#15560) | Cecylia Bocovich | |
* Enable secure cookie flag for https only * Disable force_ssl for .onion hosts only Co-authored-by: Aiden McClelland <me@drbonez.dev> | |||
2020-11-06 | Fix cookies not having a SameSite attribute (#15098) | Eugen Rochko | |