Fixed #18045 -- Corrected the documented default value of SESSION_COO…

…KIE_HTTPONLY setting. Missing bit of r17135.

@@ -1711,7 +1711,7 @@ domain cookie. See the :doc:`/topics/http/sessions`.
-Default: ``False``
+Default: ``True``
Whether to use HTTPOnly flag on the session cookie. If this is set to
``True``, client-side JavaScript will not to be able to access the
@@ -1725,6 +1725,9 @@ protected cookie data.
.. _HTTPOnly:
+.. versionchanged:: 1.4
+ The default value of the setting was changed from ``False`` to ``True``.

