From 279b5e22ccf37f0095f96b3cbe47ed77b5485cda Mon Sep 17 00:00:00 2001 From: Dan Barber Date: Fri, 17 May 2013 08:32:47 +0100 Subject: [PATCH] Only set session cookie on SSL. --- config/initializers/session_store.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/initializers/session_store.rb b/config/initializers/session_store.rb index 2eaad7f..ac1916a 100644 --- a/config/initializers/session_store.rb +++ b/config/initializers/session_store.rb @@ -1,6 +1,6 @@ # Be sure to restart your server when you modify this file. -DanBarberPhoto::Application.config.session_store :cookie_store, key: '_danbarberphoto_session' +DanBarberPhoto::Application.config.session_store :cookie_store, key: '_danbarberphoto_session', secure: true # Use the database for sessions instead of the cookie-based default, # which shouldn't be used to store highly confidential information