Skip to content

Commit ae82f73

Browse files
committed
Merge pull request #2498 from fredjiles/auth-previous-session
Add require_previous_session option to security configuration
2 parents a21215f + beaf27c commit ae82f73

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

reference/configuration/security.rst

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -147,6 +147,10 @@ Each part will be explained in the next section.
147147
# by default, the login form *must* be a POST, not a GET
148148
post_only: true
149149
remember_me: false
150+
151+
# by default, a session must exist before submitting an authentication request
152+
require_previous_session: true
153+
150154
remember_me:
151155
token_provider: name
152156
key: someS3cretKey

0 commit comments

Comments
 (0)