[tor-bugs] #2098 [Trac]: Tor Trac sets cookies over HTTPS that can be sent over cleartext HTTP

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Thu Nov 18 20:26:57 UTC 2010


#2098: Tor Trac sets cookies over HTTPS that can be sent over cleartext HTTP
----------------------+-----------------------------------------------------
 Reporter:  rransom   |       Owner:  erinn   
     Type:  defect    |      Status:  assigned
 Priority:  critical  |   Milestone:          
Component:  Trac      |     Version:          
 Keywords:            |      Parent:          
----------------------+-----------------------------------------------------

Comment(by dkg):

 See http://trac.edgewall.org/ticket/5910 for discussion.

 i think you only need to set

 {{{
 [trac]
  secure_cookies = true
 }}}

 in `trac.ini`

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/2098#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list