未验证 提交 7e40e1e3 编写于 作者: O Oleg Nenashev 提交者: GitHub

Merge pull request #4609 from StefanSpieker/spotbugs_cookie

Set httpOnly and secure on cookies to fix spotbugs issue
...@@ -4559,6 +4559,8 @@ public class Jenkins extends AbstractCIBase implements DirectlyModifiableTopLeve ...@@ -4559,6 +4559,8 @@ public class Jenkins extends AbstractCIBase implements DirectlyModifiableTopLeve
throw new ServletException(); throw new ServletException();
Cookie cookie = new Cookie("iconSize", Functions.validateIconSize(qs)); Cookie cookie = new Cookie("iconSize", Functions.validateIconSize(qs));
cookie.setMaxAge(/* ~4 mo. */9999999); // #762 cookie.setMaxAge(/* ~4 mo. */9999999); // #762
cookie.setSecure(req.isSecure());
cookie.setHttpOnly(true);
rsp.addCookie(cookie); rsp.addCookie(cookie);
String ref = req.getHeader("Referer"); String ref = req.getHeader("Referer");
if(ref==null) ref="."; if(ref==null) ref=".";
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册