aboutsummaryrefslogtreecommitdiffstats
path: root/railties/lib/rails/generators/rails
diff options
context:
space:
mode:
authorKasper Timm Hansen <kaspth@gmail.com>2018-08-12 19:02:38 +0200
committerGitHub <noreply@github.com>2018-08-12 19:02:38 +0200
commit14d3c7c2c9b89fe76a3677f99d102dd6ca729927 (patch)
tree5e3b2acdd55627088a99e91494481645e365c35e /railties/lib/rails/generators/rails
parentba1dab1e3b32a7c81cb9b8bdc22429f6620a3833 (diff)
parent1cda4fb5df519080032c9c0a16d3c4f8cf1f3d2c (diff)
downloadrails-14d3c7c2c9b89fe76a3677f99d102dd6ca729927.tar.gz
rails-14d3c7c2c9b89fe76a3677f99d102dd6ca729927.tar.bz2
rails-14d3c7c2c9b89fe76a3677f99d102dd6ca729927.zip
Merge pull request #32937 from assain/add-purpose-to-cookies
Add Purpose Metadata to Cookies
Diffstat (limited to 'railties/lib/rails/generators/rails')
-rw-r--r--railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt7
1 files changed, 7 insertions, 0 deletions
diff --git a/railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt b/railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt
index 179b97de4a..54eb0cb1d2 100644
--- a/railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt
+++ b/railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt
@@ -8,3 +8,10 @@
# Don't force requests from old versions of IE to be UTF-8 encoded
# Rails.application.config.action_view.default_enforce_utf8 = false
+
+# Embed purpose and expiry metadata inside signed and encrypted
+# cookies for increased security.
+#
+# This option is not backwards compatible with earlier Rails versions.
+# It's best enabled when your entire app is migrated and stable on 6.0.
+# Rails.application.config.action_dispatch.use_cookies_with_metadata = true