[Commotion-admin] [luci-commotion] Require sysauth cookies to be sent via web over SSL only (#28)

areynold notifications at github.com
Fri Oct 11 20:54:40 UTC 2013


Addresses commotion-openwrt issue #33 and #34.

Quick test: Visit any admin page and use the Cookies tab in Firebug to confirm that the sysauth cookie contains both the httpOnly and Secure flags.
You can merge this Pull Request by running:

  git pull https://github.com/opentechinstitute/luci-commotion sysauth-cookies-clean

Or you can view, comment on it, or merge it online at:

  https://github.com/opentechinstitute/luci-commotion/pull/28

-- Commit Summary --

  * Require sysauth cookies to be sent via web over SSL only

-- File Changes --

    M files/etc/uci-defaults/luci-proto-commotion (3)
    A files/usr/share/commotion/patches/dispatcher-cookies.patch (11)

-- Patch Links --

https://github.com/opentechinstitute/luci-commotion/pull/28.patch
https://github.com/opentechinstitute/luci-commotion/pull/28.diff
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.chambana.net/pipermail/commotion-admin/attachments/20131011/1301a250/attachment.html>


More information about the Commotion-admin mailing list