Edgewall Software

Changes between Initial Version and Version 8 of Ticket #10453


Ignore:
Timestamp:
Mar 15, 2012, 12:05:08 AM (12 years ago)
Author:
Remy Blank
Comment:

There are no .js or .html files in all of trac-hacks that reference any of the cookies defined by Trac (trac_auth, trac_session, trac_form_token). So I would say it's pretty safe to enable the httponly attribute. 10453-httponly-cookies-unconditional-r11008.patch does that.

Ok to apply?

Legend:

Unmodified
Added
Removed
Modified