Merge pull request #6735 from wenottingham/true-is-relative

Flip CSRF_COOKIE_SECURE docs.

Reviewed-by: https://github.com/apps/softwarefactory-project-zuul
This commit is contained in:
softwarefactory-project-zuul[bot]
2020-04-16 21:09:20 +00:00
committed by GitHub

View File

@@ -14,7 +14,7 @@ hijack cookies will only get the `session_id` itself, which does not imply any c
a limited time, and can be revoked at any time. a limited time, and can be revoked at any time.
> Note: The CSRF token will by default allow HTTP. To increase security, the `CSRF_COOKIE_SECURE` setting should > Note: The CSRF token will by default allow HTTP. To increase security, the `CSRF_COOKIE_SECURE` setting should
be set to False. be set to True.
## Usage ## Usage