Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with HTTPS or Subversion.

Download ZIP
Browse files

Fixed #18045 -- Corrected the documented default value of SESSION_COO…

…KIE_HTTPONLY setting. Missing bit of r17135.

git-svn-id: http://code.djangoproject.com/svn/django/trunk@17862 bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information...
commit cb2fafe57443ff499e992f6b166b6097bdb54907 1 parent b41ebcf
Claude Paroz claudep authored
Showing with 4 additions and 1 deletion.
  1. +4 −1 docs/ref/settings.txt
5 docs/ref/settings.txt
View
@@ -1711,7 +1711,7 @@ domain cookie. See the :doc:`/topics/http/sessions`.
SESSION_COOKIE_HTTPONLY
-----------------------
-Default: ``False``
+Default: ``True``
Whether to use HTTPOnly flag on the session cookie. If this is set to
``True``, client-side JavaScript will not to be able to access the
@@ -1725,6 +1725,9 @@ protected cookie data.
.. _HTTPOnly: http://www.owasp.org/index.php/HTTPOnly
+.. versionchanged:: 1.4
+ The default value of the setting was changed from ``False`` to ``True``.
+
.. setting:: SESSION_COOKIE_NAME
SESSION_COOKIE_NAME
Please sign in to comment.
Something went wrong with that request. Please try again.