Skip to content

Commit

Permalink
sys_https_host should not be left empty to benefit of the cookie pref…
Browse files Browse the repository at this point in the history
…ix protection

This is part of request #10979: Implement Same-Site cookie and cookie prefixes protections
  • Loading branch information
LeSuisse committed Jan 24, 2018
1 parent 003ef2c commit 01806d3
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions languages/en/deployment-guide/intro.rst
Expand Up @@ -39,7 +39,12 @@ you need to do it now, in ``/etc/mailman/mm_cfg.py`` change the following parame
PRIVATE_EXTERNAL_ARCHIVER = 'sudo -u codendiadm /usr/share/tuleap/plugins/forumml/bin/mail2dbng.php %(listname)s ;'


New cookies protections
-----------------------

To protect users, new cookies protection have been implemented. To make these
protections as effective as possible you should make sure the setting ``sys_https_host``
is not left empty in your ``local.inc`` if your Tuleap instance is reachable over HTTPS.

Tuleap 9.16
===========
Expand Down

0 comments on commit 01806d3

Please sign in to comment.