Files
new-api/common
CaIon 56dbaab1d4 feat(session): support opt-in Secure session cookies
- add SESSION_COOKIE_SECURE / SESSION_COOKIE_TRUSTED_URL env vars with
  startup validation: enabling Secure requires at least one trusted
  HTTPS entry URL
- wire common.SessionCookieSecure into the session cookie store instead
  of a hardcoded Secure=false
- print a startup warning when Secure session cookies are disabled
- document the new settings in .env.example and docker-compose files

Secure stays off by default because many deployments front new-api with
plain-HTTP reverse proxies, where a hardcoded Secure default would break
logins entirely; enabling it safely depends on the deployment's TLS
setup, so it ships as an opt-in deployment-hardening flag.
2026-07-05 13:53:16 +08:00
..
2024-07-07 02:24:51 +08:00
2025-07-10 20:55:43 +08:00
2025-12-02 21:34:39 +08:00
2025-07-21 15:39:16 +08:00
2025-12-19 23:16:56 +08:00
2023-04-22 20:39:27 +08:00
2025-08-03 10:41:00 +08:00
2023-04-22 20:39:27 +08:00