From cb2fafe57443ff499e992f6b166b6097bdb54907 Mon Sep 17 00:00:00 2001 From: Claude Paroz Date: Sun, 1 Apr 2012 17:13:55 +0000 Subject: [PATCH] Fixed #18045 -- Corrected the documented default value of SESSION_COOKIE_HTTPONLY setting. Missing bit of r17135. git-svn-id: http://code.djangoproject.com/svn/django/trunk@17862 bcc190cf-cafb-0310-a4f2-bffc1f526a37 --- docs/ref/settings.txt | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/docs/ref/settings.txt b/docs/ref/settings.txt index a1a0c76470..7b5c3633c6 100644 --- a/docs/ref/settings.txt +++ b/docs/ref/settings.txt @@ -1711,7 +1711,7 @@ domain cookie. See the :doc:`/topics/http/sessions`. SESSION_COOKIE_HTTPONLY ----------------------- -Default: ``False`` +Default: ``True`` Whether to use HTTPOnly flag on the session cookie. If this is set to ``True``, client-side JavaScript will not to be able to access the @@ -1725,6 +1725,9 @@ protected cookie data. .. _HTTPOnly: http://www.owasp.org/index.php/HTTPOnly +.. versionchanged:: 1.4 + The default value of the setting was changed from ``False`` to ``True``. + .. setting:: SESSION_COOKIE_NAME SESSION_COOKIE_NAME