Browse files

Improved release notes about session cookie httponly flag (#16847) pe…

…r Luke's comments.

git-svn-id: bcc190cf-cafb-0310-a4f2-bffc1f526a37
  • Loading branch information...
PaulMcMillan committed Nov 22, 2011
1 parent 98f5127 commit e13dc4905330dd2705d5b82420141b2fabab9a29
Showing with 8 additions and 3 deletions.
  1. +8 −3 docs/releases/1.4.txt
@@ -498,9 +498,6 @@ Django 1.4 also includes several smaller improvements worth noting:
* Added the :djadminopt:`--no-location` option to the :djadmin:`makemessages`
-* Changed the default value for ``httponly`` on session cookies to
- ``True`` to help reduce the impact of potential XSS attacks.
* Changed the ``locmem`` cache backend to use
``pickle.HIGHEST_PROTOCOL`` for better compatibility with the other
cache backends.
@@ -948,3 +945,11 @@ Now, the flags are keyword arguments of :meth:`@register.filter
return value
See :ref:`filters and auto-escaping <filters-auto-escaping>` for more information.
+Session cookies now have the ``httponly`` flag by default
+Session cookies now include the ``httponly`` attribute by default to
+help reduce the impact of potential XSS attacks. For strict backwards
+compatibility, use ``SESSION_COOKIE_HTTPONLY = False`` in settings.

0 comments on commit e13dc49

Please sign in to comment.