Heello / Issues

Bug and feature tracking
1 stars 0 forks source link

SECURITY: heello session cookies not marked "secure" only #6

Closed katanacrimson closed 11 years ago

katanacrimson commented 11 years ago

As on tin. This is dangerous and the cookies should be restricted to HTTPS only.

caseym commented 11 years ago

This should be updated either this evening or over the weekend. Thank you for bringing this to our attention.

caseym commented 11 years ago

Fixed. Must log out or clear the Heello session cookie to get the new secure cookie.

katanacrimson commented 11 years ago

Thanks for the dedication to getting this one fixed. I'll be poking around and seeing if I can find anything else that is noteworthy.