From 34cc56fa0caf5123ad9d929fb87964d68f1eebcf Mon Sep 17 00:00:00 2001 From: Michael Tipton Date: Fri, 12 Jan 2024 13:20:06 -0500 Subject: [PATCH] Add secure flag option for userLoggedIn cookie if SESSION_COOKIE_SECURE set to True --- awx/api/generics.py | 4 ++-- awx/sso/views.py | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/awx/api/generics.py b/awx/api/generics.py index 1081b02c7204..cb875db5b0f1 100644 --- a/awx/api/generics.py +++ b/awx/api/generics.py @@ -91,7 +91,7 @@ def post(self, request, *args, **kwargs): ret = super(LoggedLoginView, self).post(request, *args, **kwargs) if request.user.is_authenticated: logger.info(smart_str(u"User {} logged in from {}".format(self.request.user.username, request.META.get('REMOTE_ADDR', None)))) - ret.set_cookie('userLoggedIn', 'true') + ret.set_cookie('userLoggedIn', 'true', secure=getattr(settings, 'SESSION_COOKIE_SECURE', False)) ret.setdefault('X-API-Session-Cookie-Name', getattr(settings, 'SESSION_COOKIE_NAME', 'awx_sessionid')) return ret @@ -107,7 +107,7 @@ def dispatch(self, request, *args, **kwargs): original_user = getattr(request, 'user', None) ret = super(LoggedLogoutView, self).dispatch(request, *args, **kwargs) current_user = getattr(request, 'user', None) - ret.set_cookie('userLoggedIn', 'false') + ret.set_cookie('userLoggedIn', 'false', secure=getattr(settings, 'SESSION_COOKIE_SECURE', False)) if (not current_user or not getattr(current_user, 'pk', True)) and current_user != original_user: logger.info("User {} logged out.".format(original_user.username)) return ret diff --git a/awx/sso/views.py b/awx/sso/views.py index c4ecdc763239..c23ee4428adc 100644 --- a/awx/sso/views.py +++ b/awx/sso/views.py @@ -38,7 +38,7 @@ def dispatch(self, request, *args, **kwargs): response = super(CompleteView, self).dispatch(request, *args, **kwargs) if self.request.user and self.request.user.is_authenticated: logger.info(smart_str(u"User {} logged in".format(self.request.user.username))) - response.set_cookie('userLoggedIn', 'true') + response.set_cookie('userLoggedIn', 'true', secure=getattr(settings, 'SESSION_COOKIE_SECURE', False)) response.setdefault('X-API-Session-Cookie-Name', getattr(settings, 'SESSION_COOKIE_NAME', 'awx_sessionid')) return response