mirror of
https://github.com/ansible/awx.git
synced 2026-02-15 10:10:01 -03:30
make current_user ck secure and httponly
This commit is contained in:
@@ -92,8 +92,7 @@ class LoggedLoginView(auth_views.LoginView):
|
||||
current_user = UserSerializer(self.request.user)
|
||||
current_user = JSONRenderer().render(current_user.data)
|
||||
current_user = urllib.quote('%s' % current_user, '')
|
||||
ret.set_cookie('current_user', current_user)
|
||||
|
||||
ret.set_cookie('current_user', current_user, secure=settings.SESSION_COOKIE_SECURE or None)
|
||||
return ret
|
||||
else:
|
||||
ret.status_code = 401
|
||||
|
||||
Reference in New Issue
Block a user