Set CSRF cookie as httpOnly

This commit is contained in:
Jake Howard 2024-01-05 15:59:23 +00:00
parent 307cd7fe26
commit 166441b3e3
Signed by: jake
GPG key ID: 57AFB45680EDD477

View file

@ -398,9 +398,6 @@ SESSION_COOKIE_AGE = 2419200 # About a month
CSRF_COOKIE_SECURE = not DEBUG CSRF_COOKIE_SECURE = not DEBUG
SESSION_COOKIE_HTTPONLY = True SESSION_COOKIE_HTTPONLY = True
# https://github.com/wagtail/wagtail-autocomplete/issues/149
CSRF_COOKIE_HTTPONLY = False
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https") SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
PERMISSIONS_POLICY: dict[str, list] = { PERMISSIONS_POLICY: dict[str, list] = {