diff --git a/apimanager/apimanager/settings.py b/apimanager/apimanager/settings.py index 16e6c064..851afe3d 100644 --- a/apimanager/apimanager/settings.py +++ b/apimanager/apimanager/settings.py @@ -284,6 +284,13 @@ # Always save session$ SESSION_SAVE_EVERY_REQUEST = True +# Session Cookie Settings +SESSION_COOKIE_SECURE = True +SESSION_COOKIE_HTTPONLY = True +SESSION_COOKIE_AGE = 300 +SESSION_ENGINE = "django.contrib.sessions.backends.signed_cookies" + + # Paths on API_HOST to OAuth OAUTH_TOKEN_PATH = '/oauth/initiate' OAUTH_AUTHORIZATION_PATH = '/oauth/authorize'