By using this site, you agree to have cookies stored on your device, strictly for functional purposes, such as storing your session and preferences.


Session cookie security

created on Tuesday, 7 May 2024, 13:15:50 (1715087750), received on Wednesday, 31 July 2024, 06:54:48 (1722408888)
Author identity: vlad <>


@@ -29,7 +29,7 @@ from common import git_command

                                            from flask_babel import Babel, gettext, ngettext, force_locale
                                            _ = gettext
                                        n_ = gettext
                                        n_ = ngettext
                                            app = flask.Flask(__name__)

@@ -47,6 +47,10 @@ app.config["SECRET_KEY"] = config.DB_PASSWORD

                                            app.config["SQLALCHEMY_TRACK_MODIFICATIONS"] = False
                                            app.config["BABEL_TRANSLATION_DIRECTORIES"] = "i18n"
                                            app.config["MAX_CONTENT_LENGTH"] = config.MAX_PAYLOAD_SIZE
                                        app.config["SESSION_COOKIE_SAMESITE"] = "Lax"
                                        app.config["SESSION_COOKIE_SECURE"] = config.suggest_https       # only send cookies over HTTPS if the server is configured for it
                                        app.config["SESSION_COOKIE_HTTPONLY"] = True                     # don't allow JS to access the cookie
                                        app.config["SESSION_COOKIE_DOMAIN"] = config.BASE_DOMAIN         # don't share across subdomains, since user content is hosted there
                                            db = SQLAlchemy(app)
                                            bcrypt = Bcrypt(app)