Login

Add httponly to session cookie

Author:
rodolfo.3
Posted:
April 12, 2010
Language:
Python
Version:
1.1
Tags:
cookie security httponly
Score:
1 (after 1 ratings)

Middleware to set "sessionid" (ou your session cookie) with httponly (see "Django bug report"). To work, you need put it before "SessionMiddleware"

1
2
3
4
5
6
7
from django.conf import settings

class cookie_httponly:
    def process_response(self, request, response):
        if response.cookies.has_key(settings.SESSION_COOKIE_NAME):
            response.cookies[settings.SESSION_COOKIE_NAME]['httponly'] = True
        return response

More like this

  1. Automatically setup raw_id_fields ForeignKey & OneToOneField by agusmakmun 6 months, 2 weeks ago
  2. Crispy Form by sourabhsinha396 7 months, 1 week ago
  3. ReadOnlySelect by mkoistinen 7 months, 3 weeks ago
  4. Verify events sent to your webhook endpoints by santos22 8 months, 2 weeks ago
  5. Django Language Middleware by agusmakmun 9 months ago

Comments

arthur (on October 4, 2011):

Django 1.3 includes a SESSION_COOKIE_HTTPONLY setting.

#

Please login first before commenting.