Skip to content
Commit d92b172a authored by StefanSpieker's avatar StefanSpieker Committed by Oleg Nenashev
Browse files

Set the HttpOnly flag for the page auto-refresh tokens (#4363)



* set HttpOnly flag to prevent cookie read by a malicious script in browser

* Update core/src/main/java/hudson/Functions.java

Co-Authored-By: default avatarWadeck Follonier <Wadeck@users.noreply.github.com>
parent fd02997e
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment