-
Notifications
You must be signed in to change notification settings - Fork 10.1k
Closed
Description
I noticed that socket.io (engine.io to be precise) is setting a non-secure session cookie called 'io' on the URL it is invoked. What is the role of this cookie, is it necessary and if so, can it be secured? We force https:// for all locations where socket.io is running, and could easily set this cookie to secure but I cannot find where.
clarketm, lwille, patrickd-, timnoorlander, guyfawcus and 4 more
Metadata
Metadata
Assignees
Labels
No labels