Use secure session cookies

Django would be default use insecure cookies - that would be sent by the
browser also over plain http.  And administrative work requiring authenticated
sessions should be done over https - and therefore, the cookie should be marked
as secure.

This can be achived by setting:

    settings.SESSION_COOKIE_SECURE = True

As this is an essential security setting that shouldn't need additional tweaks,
adding the setting to (and not
......@@ -213,6 +213,8 @@ EDUROAM_KML_URL = ''
# Check for headers indicating the request was received on a secure SSL connection
SECURE_PROXY_SSL_HEADER = ('X-Forwarded-SSL', 'on')
# Request session cookies to be marked as secure
TINYMCE_JS_URL = '/static/js/tinymce/tiny_mce.js'
