-
- Downloads
Onion service related changes to HTTPS handling (#15560)
* Enable secure cookie flag for https only
* Disable force_ssl for .onion hosts only
Co-authored-by:
Aiden McClelland <me@drbonez.dev>
Showing
- Gemfile 2 additions, 0 deletionsGemfile
- Gemfile.lock 4 additions, 0 deletionsGemfile.lock
- app/controllers/application_controller.rb 1 addition, 1 deletionapp/controllers/application_controller.rb
- app/lib/webfinger.rb 10 additions, 2 deletionsapp/lib/webfinger.rb
- config/initializers/devise.rb 0 additions, 6 deletionsconfig/initializers/devise.rb
- config/initializers/makara.rb 0 additions, 1 deletionconfig/initializers/makara.rb
- config/initializers/secureheaders.rb 10 additions, 0 deletionsconfig/initializers/secureheaders.rb
- config/initializers/session_store.rb 0 additions, 1 deletionconfig/initializers/session_store.rb
... | ... | @@ -161,3 +161,5 @@ gem 'connection_pool', require: false |
gem 'xorcist', '~> 1.1' | ||
gem 'pluck_each', '~> 0.1.3' | ||
gem 'secure_headers', '~> 3.5' |
config/initializers/secureheaders.rb
0 → 100644
Please register or sign in to comment