Skip to content

Enabling HTTPS in production #11

@mattdowdell

Description

@mattdowdell

Once HTTPS is enabled in production, a few minor changes can be made to improve security:

  • Make cookies HTTPS only by setting the secure attribute.
  • Set the force_ssh attribute in production configuration.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions