Browse Source

!120 set cookie is httpOnly in CaptchaRender
Merge pull request !120 from Michael Yang/N/A

JFinal 1 year ago
parent
commit
66b12aa5eb
1 changed files with 1 additions and 0 deletions
  1. 1 0
      src/main/java/com/jfinal/captcha/CaptchaRender.java

+ 1 - 0
src/main/java/com/jfinal/captcha/CaptchaRender.java

@@ -86,6 +86,7 @@ public class CaptchaRender extends Render {
 		Cookie cookie = new Cookie(captchaName, captcha.getKey());
 		cookie.setMaxAge(-1);
 		cookie.setPath("/");
+        cookie.setHttpOnly(true);
 		response.addCookie(cookie);
 		response.setHeader("Pragma","no-cache");
 		response.setHeader("Cache-Control","no-cache");