rememberable cookie now is httponly by default

This commit is contained in:
José Valim
2010-12-25 12:04:04 +01:00
parent 1b43cb5203
commit af1295284c
3 changed files with 7 additions and 3 deletions

View File

@@ -18,11 +18,14 @@ module Devise
def cookie_values(resource)
options = Rails.configuration.session_options.slice(:path, :domain, :secure)
options[:httponly] = true
options.merge!(resource.cookie_options)
options.merge!(
:value => resource.class.serialize_into_cookie(resource),
:expires => resource.remember_expires_at
)
options
end