Drop dependency on secure_headers, fix response headers (#15712)
* Drop dependency on secure_headers, use always_write_cookie instead * Fix cookies in Tor Hidden Services by moving configuration to application.rb * Instead of setting always_write_cookie at boot, monkey-patch ActionDispatch
Showing
- Gemfile 0 additions, 2 deletionsGemfile
- Gemfile.lock 0 additions, 4 deletionsGemfile.lock
- config/application.rb 1 addition, 0 deletionsconfig/application.rb
- config/initializers/devise.rb 6 additions, 0 deletionsconfig/initializers/devise.rb
- config/initializers/makara.rb 1 addition, 0 deletionsconfig/initializers/makara.rb
- config/initializers/secureheaders.rb 0 additions, 10 deletionsconfig/initializers/secureheaders.rb
- config/initializers/session_store.rb 1 addition, 0 deletionsconfig/initializers/session_store.rb
- lib/action_dispatch/cookie_jar_extensions.rb 15 additions, 0 deletionslib/action_dispatch/cookie_jar_extensions.rb
... | ... | @@ -161,5 +161,3 @@ gem 'connection_pool', require: false |
gem 'xorcist', '~> 1.1' | ||
gem 'pluck_each', '~> 0.1.3' | ||
gem 'secure_headers', '~> 3.5' |
config/initializers/secureheaders.rb
deleted
100644 → 0
lib/action_dispatch/cookie_jar_extensions.rb
0 → 100644
Please register or sign in to comment