summaryrefslogtreecommitdiff
path: root/htetc
diff options
context:
space:
mode:
authorIvan Kohler <ivan@freeside.biz>2016-09-25 11:12:09 -0700
committerIvan Kohler <ivan@freeside.biz>2016-09-25 11:12:09 -0700
commitdd21870b44d5557e9bff786c0476012c151f035a (patch)
tree15ada0eb94bed865c416b9ace95de98b52523fe5 /htetc
parent915c0aef4455a88a53ac4f0d2f95e0b88b22c4bd (diff)
document these non-well-named Apache::AuthCookieHandler options
Diffstat (limited to 'htetc')
-rw-r--r--htetc/freeside-base2.4.conf4
-rw-r--r--htetc/freeside-base2.conf4
2 files changed, 4 insertions, 4 deletions
diff --git a/htetc/freeside-base2.4.conf b/htetc/freeside-base2.4.conf
index f0b44d7..ee716f3 100644
--- a/htetc/freeside-base2.4.conf
+++ b/htetc/freeside-base2.4.conf
@@ -20,8 +20,8 @@ PerlAddAuthzProvider user FS::AuthCookieHandler24->authz_handler
#XXX need to also work properly for installs w/o /freeside/ in path
PerlSetVar FreesideLoginScript /freeside/loginout/login.html
-#PerlSetVar FreesideEverSecure 1
-PerlSetVar FreesideHttpOnly 1
+#PerlSetVar FreesideSecure 1 #disables HTTP, so HTTPS only
+PerlSetVar FreesideHttpOnly 1 #limits cookie theft via JS
<Directory %%%FREESIDE_DOCUMENT_ROOT%%%>
diff --git a/htetc/freeside-base2.conf b/htetc/freeside-base2.conf
index 309279d..6a1d2fb 100644
--- a/htetc/freeside-base2.conf
+++ b/htetc/freeside-base2.conf
@@ -18,8 +18,8 @@ PerlModule FS::AuthCookieHandler
#XXX need to also work properly for installs w/o /freeside/ in path
PerlSetVar FreesideLoginScript /freeside/loginout/login.html
-#PerlSetVar FreesideEverSecure 1
-PerlSetVar FreesideHttpOnly 1
+#PerlSetVar FreesideSecure 1 #disables HTTP, so HTTPS only
+PerlSetVar FreesideHttpOnly 1 #limits cookie theft via JS
<Directory %%%FREESIDE_DOCUMENT_ROOT%%%>