From b0e0f2368473e4e953acf18aea9b7673066ceff5 Mon Sep 17 00:00:00 2001 From: elijah Date: Tue, 12 Feb 2013 21:33:59 -0800 Subject: disable cookies --- config/initializers/secret_token.rb | 3 ++- config/initializers/session_store.rb | 2 +- 2 files changed, 3 insertions(+), 2 deletions(-) (limited to 'config') diff --git a/config/initializers/secret_token.rb b/config/initializers/secret_token.rb index 06a5a97..1b030e7 100644 --- a/config/initializers/secret_token.rb +++ b/config/initializers/secret_token.rb @@ -4,4 +4,5 @@ # If you change this key, all old signed cookies will become invalid! # Make sure the secret is at least 30 characters and all random, # no regular words or you'll be exposed to dictionary attacks. -LeapPublicSite::Application.config.secret_token = '10688238554c5f6c69eccd3f675f754451d7a4a522525f0ca118d939ec586bacdde1387415f50749330082f5af38941da8c7835692b668aa60e48224c12fdb13' + +# LeapPublicSite::Application.config.secret_token = '' diff --git a/config/initializers/session_store.rb b/config/initializers/session_store.rb index bdc93f8..52ff2dd 100644 --- a/config/initializers/session_store.rb +++ b/config/initializers/session_store.rb @@ -1,6 +1,6 @@ # Be sure to restart your server when you modify this file. -LeapPublicSite::Application.config.session_store :cookie_store, :key => '_leap-public-site_session' +LeapPublicSite::Application.config.session_store :disabled #:cookie_store, :key => '_leap-public-site_session' # Use the database for sessions instead of the cookie-based default, # which shouldn't be used to store highly confidential information -- cgit v1.2.3