[openstreetmap/openstreetmap-website] Set secure and httponly attributes for TOTP cookie (PR #7045)

Tom Hughes notifications at github.com
Tue Apr 28 18:08:54 UTC 2026


I don't think either matters much (and secure is defaulting to on in production anyway) but it doesn't do any harm either.
You can view, comment on, or merge this pull request online at:

  https://github.com/openstreetmap/openstreetmap-website/pull/7045

-- Commit Summary --

  * Set secure and httponly attributes for TOTP cookie

-- File Changes --

    M app/controllers/application_controller.rb (4)

-- Patch Links --

https://github.com/openstreetmap/openstreetmap-website/pull/7045.patchhttps://github.com/openstreetmap/openstreetmap-website/pull/7045.diff
-- 
Reply to this email directly or view it on GitHub:
https://github.com/openstreetmap/openstreetmap-website/pull/7045
You are receiving this because you are subscribed to this thread.

Message ID: <openstreetmap/openstreetmap-website/pull/7045 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstreetmap.org/pipermail/rails-dev/attachments/20260428/0301191c/attachment.htm>


More information about the rails-dev mailing list