diff options
author | Assain <assainjaleel20@gmail.com> | 2018-05-19 13:31:57 +0530 |
---|---|---|
committer | Assain <assainjaleel20@gmail.com> | 2018-08-12 21:50:35 +0530 |
commit | 1cda4fb5df519080032c9c0a16d3c4f8cf1f3d2c (patch) | |
tree | 5e3b2acdd55627088a99e91494481645e365c35e /railties/lib/rails/generators/rails | |
parent | ba1dab1e3b32a7c81cb9b8bdc22429f6620a3833 (diff) | |
download | rails-1cda4fb5df519080032c9c0a16d3c4f8cf1f3d2c.tar.gz rails-1cda4fb5df519080032c9c0a16d3c4f8cf1f3d2c.tar.bz2 rails-1cda4fb5df519080032c9c0a16d3c4f8cf1f3d2c.zip |
Purpose Metadata For Signed And Encrypted Cookies
Purpose metadata prevents cookie values from being
copy-pasted and ensures that the cookie is used only
for its originally intended purpose.
The Purpose and Expiry metadata are embedded inside signed/encrypted
cookies and will not be readable on previous versions of Rails.
We can switch off purpose and expiry metadata embedded in
signed and encrypted cookies using
config.action_dispatch.use_cookies_with_metadata = false
if you want your cookies to be readable on older versions of Rails.
Diffstat (limited to 'railties/lib/rails/generators/rails')
-rw-r--r-- | railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt b/railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt index 179b97de4a..54eb0cb1d2 100644 --- a/railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt +++ b/railties/lib/rails/generators/rails/app/templates/config/initializers/new_framework_defaults_6_0.rb.tt @@ -8,3 +8,10 @@ # Don't force requests from old versions of IE to be UTF-8 encoded # Rails.application.config.action_view.default_enforce_utf8 = false + +# Embed purpose and expiry metadata inside signed and encrypted +# cookies for increased security. +# +# This option is not backwards compatible with earlier Rails versions. +# It's best enabled when your entire app is migrated and stable on 6.0. +# Rails.application.config.action_dispatch.use_cookies_with_metadata = true |