Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Support JSON Property for HTTPOnly To enable it, set sessionStateHttpOnly: true in oxAuth config. Note that SessionManagement will not work. See http://openid.net/specs/openid-connect-session-1_0.html Note that your browser should not allow a client-side script to access the session_state cookie. Unfortunately, since the attribute is relatively new, several browsers may neglect to handle the new attribute properly. See https://www.owasp.org/index.php/HttpOnly
- Loading branch information