SetCookieOptions missing the secure flag missing

Are all cookies now considered secure?  or does this need exposing in SetCookieOptions?

Parents Reply
  • Without explicitly setting the Secure attribute in your SetCookieOptions, browsers will still gladly transmit that cookie over an unencrypted plain HTTP request (for example, if a user types http:// instead of https:// before your server redirects them).

    To prevent network eavesdropping and session hijacking during that initial unencrypted window, the Secure flag must be manually and explicitly enabled.
Children