Prechádzať zdrojové kódy

Refs #28741 -- Doc'd SESSION_COOKIE_DOMAIN requirement with CSRF_USE_SESSIONS.

Similar considerations as refs #32065, again adding some nuance to
afd375fc343baa46e61036087bc43b3d096bb0ca.
Tim Graham 4 rokov pred
rodič
commit
2e7ba6057c
1 zmenil súbory, kde vykonal 4 pridanie a 0 odobranie
  1. 4 0
      docs/ref/settings.txt

+ 4 - 0
docs/ref/settings.txt

@@ -3167,6 +3167,10 @@ The domain to use for session cookies. Set this to a string such as
 ``"example.com"`` for cross-domain cookies, or use ``None`` for a standard
 domain cookie.
 
+To use cross-domain cookies with :setting:`CSRF_USE_SESSIONS`, you must include
+a leading dot (e.g. ``".example.com"``) to accommodate the CSRF middleware's
+referer checking.
+
 Be cautious when updating this setting on a production site. If you update
 this setting to enable cross-domain cookies on a site that previously used
 standard domain cookies, existing user cookies will be set to the old