Are all cookies now considered secure? or does this need exposing in SetCookieOptions?
Are all cookies now considered secure? or does this need exposing in SetCookieOptions?
If the site is running HTTPS then cookies are secured automatically.
Secure attribute in your SetCookieOptions, browsers will still gladly transmit that cookie over an unencrypted plain HTTP request (for example, if a user types http:// instead of https:// before your server redirects them).Secure flag must be manually and explicitly enabled.We detect that a site is using HTTPS and explicitly set the flag before being sent, it is encapsulated internally.
We detect that a site is using HTTPS and explicitly set the flag before being sent, it is encapsulated internally.