MY-RIDE icon indicating copy to clipboard operation
MY-RIDE copied to clipboard

Secure Setting for Django `SESSION_COOKIE_SECURE` flag

Open pixeebot[bot] opened this issue 1 year ago • 2 comments

This codemod will set Django's SESSION_COOKIE_SECURE flag to True if it's False or missing on the settings.py file within Django's default directory structure.

+ SESSION_COOKIE_SECURE = True

Setting this flag on ensures that the session cookies are only sent under an HTTPS connection. Leaving this flag off may enable an attacker to use a sniffer to capture the unencrypted session cookie and hijack the user's session.

More reading

🧚🤖 Powered by Pixeebot

Feedback | Community | Docs | Codemod ID: pixee:python/django-session-cookie-secure-off

pixeebot[bot] avatar Jul 17 '24 08:07 pixeebot[bot]

I'm confident in this change, but I'm not a maintainer of this project. Do you see any reason not to merge it?

If this change was not helpful, or you have suggestions for improvements, please let me know!

pixeebot[bot] avatar Jul 25 '24 03:07 pixeebot[bot]

Just a friendly ping to remind you about this change. If there are concerns about it, we'd love to hear about them!

pixeebot[bot] avatar Jul 26 '24 03:07 pixeebot[bot]

This change may not be a priority right now, so I'll close it. If there was something I could have done better, please let me know!

You can also customize me to make sure I'm working with you in the way you want.

pixeebot[bot] avatar Aug 01 '24 03:08 pixeebot[bot]