[PR #130] fix: always set secure on cookie #949

Closed
opened 2025-10-07 00:25:10 +03:00 by OVERLORD · 0 comments
Owner

Original Pull Request: https://github.com/pocket-id/pocket-id/pull/130

State: closed
Merged: Yes


HTTPS is required for WebAuthn, so there's no downside to enabling this. And it prevents accidentally leaking an access token to the network in cleartext on an initial HTTP connection.

**Original Pull Request:** https://github.com/pocket-id/pocket-id/pull/130 **State:** closed **Merged:** Yes --- HTTPS is required for WebAuthn, so there's no downside to enabling this. And it prevents accidentally leaking an access token to the network in cleartext on an initial HTTP connection.
OVERLORD added the pull-request label 2025-10-07 00:25:11 +03:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/pocket-id#949