New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Force secure cookie on HTTPS connection #6924
Merged
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
yguedidi
requested changes
Sep 6, 2023
j0k3r
force-pushed
the
fix/secure-cookie
branch
from
September 6, 2023 10:39
f523d2f
to
c5d2102
Compare
yguedidi
approved these changes
Sep 6, 2023
mweinelt
added a commit
to mweinelt/nixpkgs
that referenced
this pull request
Sep 9, 2023
https://github.com/wallabag/wallabag/releases/tag/2.6.0 https://github.com/wallabag/wallabag/releases/tag/2.6.1 https://github.com/wallabag/wallabag/releases/tag/2.6.2 https://github.com/wallabag/wallabag/releases/tag/2.6.3 https://github.com/wallabag/wallabag/releases/tag/2.6.4 https://github.com/wallabag/wallabag/releases/tag/2.6.5 https://github.com/wallabag/wallabag/releases/tag/2.6.6 Dropped the swiftmailer patch, because wallabag migrated to symfony mailer. GHSA-p8gp-899c-jvq9 GHSA-gjvc-55fw-v6vq wallabag/wallabag#6924 Fixes: CVE-2023-4454, CVE-2023-4455
mweinelt
added a commit
to mweinelt/nixpkgs
that referenced
this pull request
Sep 9, 2023
https://github.com/wallabag/wallabag/releases/tag/2.6.0 https://github.com/wallabag/wallabag/releases/tag/2.6.1 https://github.com/wallabag/wallabag/releases/tag/2.6.2 https://github.com/wallabag/wallabag/releases/tag/2.6.3 https://github.com/wallabag/wallabag/releases/tag/2.6.4 https://github.com/wallabag/wallabag/releases/tag/2.6.5 https://github.com/wallabag/wallabag/releases/tag/2.6.6 Dropped the swiftmailer patch, because wallabag migrated to symfony mailer. GHSA-p8gp-899c-jvq9 GHSA-gjvc-55fw-v6vq wallabag/wallabag#6924 Fixes: CVE-2023-4454, CVE-2023-4455
github-actions bot
pushed a commit
to NixOS/nixpkgs
that referenced
this pull request
Sep 9, 2023
https://github.com/wallabag/wallabag/releases/tag/2.6.0 https://github.com/wallabag/wallabag/releases/tag/2.6.1 https://github.com/wallabag/wallabag/releases/tag/2.6.2 https://github.com/wallabag/wallabag/releases/tag/2.6.3 https://github.com/wallabag/wallabag/releases/tag/2.6.4 https://github.com/wallabag/wallabag/releases/tag/2.6.5 https://github.com/wallabag/wallabag/releases/tag/2.6.6 Dropped the swiftmailer patch, because wallabag migrated to symfony mailer. GHSA-p8gp-899c-jvq9 GHSA-gjvc-55fw-v6vq wallabag/wallabag#6924 Fixes: CVE-2023-4454, CVE-2023-4455 (cherry picked from commit 0f9a86c)
ivandimitrov8080
pushed a commit
to ivandimitrov8080/nixpkgs
that referenced
this pull request
Sep 10, 2023
https://github.com/wallabag/wallabag/releases/tag/2.6.0 https://github.com/wallabag/wallabag/releases/tag/2.6.1 https://github.com/wallabag/wallabag/releases/tag/2.6.2 https://github.com/wallabag/wallabag/releases/tag/2.6.3 https://github.com/wallabag/wallabag/releases/tag/2.6.4 https://github.com/wallabag/wallabag/releases/tag/2.6.5 https://github.com/wallabag/wallabag/releases/tag/2.6.6 Dropped the swiftmailer patch, because wallabag migrated to symfony mailer. GHSA-p8gp-899c-jvq9 GHSA-gjvc-55fw-v6vq wallabag/wallabag#6924 Fixes: CVE-2023-4454, CVE-2023-4455
wegank
pushed a commit
to NixOS/nixpkgs
that referenced
this pull request
Sep 16, 2023
https://github.com/wallabag/wallabag/releases/tag/2.6.0 https://github.com/wallabag/wallabag/releases/tag/2.6.1 https://github.com/wallabag/wallabag/releases/tag/2.6.2 https://github.com/wallabag/wallabag/releases/tag/2.6.3 https://github.com/wallabag/wallabag/releases/tag/2.6.4 https://github.com/wallabag/wallabag/releases/tag/2.6.5 https://github.com/wallabag/wallabag/releases/tag/2.6.6 Dropped the swiftmailer patch, because wallabag migrated to symfony mailer. GHSA-p8gp-899c-jvq9 GHSA-gjvc-55fw-v6vq wallabag/wallabag#6924 Fixes: CVE-2023-4454, CVE-2023-4455 (cherry picked from commit 0f9a86c)
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Cookie will be set as
secure
when the connection will be on HTTPS otherwise the cookie will be defined assecure: false
.I used
mkcert
to test it locally.See: