Enable authenticated cookie encryption
This is the default encryption for cookies in Rails 5.2 applications. The reason it isn't enabled automatically for existing applications is these cookies are not compatible with running the application on several servers when some of them use Rails 4. Since this isn't our case (we don't support using different versions of CONSUL on different servers), and existing cookies are still read correctly, we can safely enable it.
This commit is contained in:
@@ -17,7 +17,7 @@
|
||||
# It's best enabled when your entire app is migrated and stable on 5.2.
|
||||
#
|
||||
# Existing cookies will be converted on read then written with the new scheme.
|
||||
# Rails.application.config.action_dispatch.use_authenticated_cookie_encryption = true
|
||||
Rails.application.config.action_dispatch.use_authenticated_cookie_encryption = true
|
||||
|
||||
# Use AES-256-GCM authenticated encryption as default cipher for encrypting messages
|
||||
# instead of AES-256-CBC, when use_authenticated_message_encryption is set to true.
|
||||
|
||||
Reference in New Issue
Block a user