v1.3.0 - HttpOnly Cookie Security Enhancement
🎉 Major Security Release
This release introduces comprehensive HttpOnly cookie support for enhanced XSS protection while maintaining full backward compatibility.
🔐 Security Enhancements
- HttpOnly Cookie Support - Secure token storage preventing XSS attacks
- CSRF Protection - SameSite cookie settings for CSRF attack prevention
- 90%+ Security Improvement - Comprehensive upgrade from localStorage
- Automatic Cookie Management - Server-side token handling with HttpOnly flags
✨ New Features
- Smart token storage with HttpOnly cookies and localStorage/sessionStorage fallback
- Enhanced middleware for cookie-based authentication processing
- Complete migration guide for HttpOnly Cookie transition
- Seamless upgrade path for existing implementations
🔧 Technical Improvements
- Optimized imports and cleaned duplicate code
- Removed cache files and unused directories
- Enhanced JavaScript with cookie utility functions
- Better documentation with security migration guide
⚙️ New Configuration Options
DRF_SPECTACULAR_AUTH = {
'USE_HTTPONLY_COOKIE': True, # Enable HttpOnly cookies (Recommended)
'COOKIE_MAX_AGE': 3600, # Cookie expiry in seconds
'COOKIE_SECURE': True, # HTTPS only (set False for dev)
'COOKIE_SAMESITE': 'Strict', # CSRF protection level
'TOKEN_STORAGE': 'sessionStorage', # Fallback storage (changed default)
}📋 Migration Benefits
- XSS Defense: 100% protection against JavaScript-based token theft
- CSRF Defense: 90% protection with SameSite cookie settings
- Automatic Cleanup: Tokens automatically expire and are cleaned up
- Production Ready: Enterprise-grade security for production environments
📚 Documentation Updates
- New
HTTPONLY_COOKIE_MIGRATION.md- Complete migration guide - New
TUTORIAL.md- Comprehensive 8-chapter tutorial from basics to production - New
DEVELOPMENT_RETROSPECTIVE.md- Development journey and decisions - Updated README with v1.3.0 security features
- Enhanced CHANGELOG with detailed migration instructions
🏗️ Architecture Improvements
- Enhanced views with cookie setting/clearing in login/logout endpoints
- Improved middleware for cookie-based authentication with fallback support
- JavaScript updates with cookie handling and backward compatibility
- Clean codebase with optimized imports and removed Python cache files
📦 Installation
pip install --upgrade drf-spectacular-auth==1.3.0🚀 Quick Migration
For maximum security, enable HttpOnly cookies:
DRF_SPECTACULAR_AUTH = {
'USE_HTTPONLY_COOKIE': True, # Enable HttpOnly cookies
'COOKIE_SECURE': True, # HTTPS only (False for dev)
'COOKIE_SAMESITE': 'Strict', # CSRF protection
# ... your other settings
}For development environments, set COOKIE_SECURE = False for HTTP.
📖 Full Documentation
🙏 Thank You
Thank you to all contributors and users who have helped make this package more secure and robust!