Skip to content

Commit 3e1c1ba

Browse files
committed
Ensure HttpOnly, Secure and Domain are set for new sessions
1 parent ea2757e commit 3e1c1ba

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

sqlitestore.go

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -125,8 +125,11 @@ func (m *SqliteStore) Get(r *http.Request, name string) (*sessions.Session, erro
125125
func (m *SqliteStore) New(r *http.Request, name string) (*sessions.Session, error) {
126126
session := sessions.NewSession(m, name)
127127
session.Options = &sessions.Options{
128-
Path: m.Options.Path,
129-
MaxAge: m.Options.MaxAge,
128+
Domain: m.Options.Domain,
129+
HttpOnly: m.Options.HttpOnly,
130+
MaxAge: m.Options.MaxAge,
131+
Path: m.Options.Path,
132+
Secure: m.Options.Secure,
130133
}
131134
session.IsNew = true
132135
var err error

0 commit comments

Comments
 (0)