Hacker News new | ask | show | jobs
by rtomayko 5702 days ago
We fat fingered the config. The cookie is marked secure now but we found another issue where it's being sent back on redirected HTTP requests. It should be all plugged up in a bit.
1 comments

Okay. The session cookie is marked secure and is sent only in response to HTTPS requests. That should cover everything.
Somebody get this guy some karma.