Repository navigation
feat(session)!: default the session cookie to __Host-session with Secure - #415
Merged
Merged
Conversation
SessionConfig.cookie_name defaults to "__Host-session" and cookie_https_only to True. Browsers accept a __Host- cookie only when it is Secure, has Path=/ and no Domain, and never from a subdomain, which removes the usual way to plant a session cookie. A __Host- name without Secure, with a cookie_path other than "/" or with a cookie_domain, and a __Secure- name without Secure, now raise a ValidationError instead of the 0.3.9 UserWarning. The message says when the name is the default and suggests a fix that fits the problem. The SameSite=None warning no longer fires for a prefixed name, which the prefix check already rejects. The middleware's FutureWarning about the cookie defaults is removed. BREAKING CHANGE: the session cookie is renamed to __Host-session and is Secure by default, so every cookie session is logged out once after the upgrade and the cookie is not sent over plain HTTP. For plain-HTTP development, set cookie_name="session", cookie_https_only=False. Setting only cookie_https_only=False, cookie_path or cookie_domain with the default name now raises. Refs #256
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #256 (part 4 of the proposal: cookie defaults).
logout(), read-onlySession.userandkeep=follow in a separate PR, so this one does not close the issue.Changes
SessionConfig.cookie_namedefaults to"__Host-session"andcookie_https_onlytoTrue.ValidationErrorinstead of the 0.3.9UserWarning:__Host-name without Secure, with acookie_pathother than"/"or with acookie_domain;__Secure-name without Secure.__Host-session, setting onlycookie_https_only=False,cookie_pathorcookie_domainalso raises. The message:(the default);cookie_name='session', cookie_https_only=Falsefor plain HTTP;cookie_name='__Secure-session'for a path or domain, so the Secure flag is kept;SameSite=Nonewarning no longer fires for a prefixed name, which the prefix check already rejects.FutureWarningabout the cookie defaults is removed.SESSION.md: the "Cookie defaults" section, the config reference, and the HTTPS-only section.MIGRATING_0_4.md#session-cookie: the default-name case, and the note that 0.3.9 warned about it only under the middleware.Tests
__Host-session=…; path=/; secure, noDomain).