Flip CSRF_COOKIE_SECURE docs.

I think this was backwards.
This commit is contained in:
Bill Nottingham 2020-04-16 15:34:31 -04:00
parent f47325a532
commit 11b1d0e84c

View File

@ -14,7 +14,7 @@ hijack cookies will only get the `session_id` itself, which does not imply any c
a limited time, and can be revoked at any time.
> Note: The CSRF token will by default allow HTTP. To increase security, the `CSRF_COOKIE_SECURE` setting should
be set to False.
be set to True.
## Usage